CVE-2024-51228
totolink a3002ru Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2024-51228 has a selected CVSS score of 6.8 (medium); EIP currently links 1 Nuclei template.
Description
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 29, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 29, 2024 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
a3002ruBrowse totolink / a3002ru | VulnCheck | Version data not supplied | |
a3002ru_firmwareBrowse totolink / a3002ru_firmwareDefault status: unknown | CVE List | 1.0.4-B20171106.1512 | affected |
n150rt_firmwareBrowse totolink / n150rt_firmwareDefault status: unknown | CVE List | 2.1.6-B20171121.1002 | affected |
n300rt_firmwareBrowse totolink / n300rt_firmwareDefault status: unknown | CVE List | 2.1.6-B20170724.1420 | affected |
| 2.1.8-B20171113.1408 | affected | ||
| 2.1.8-B20191010.1107 | affected | ||
n302re_firmwareBrowse totolink / n302re_firmwareDefault status: unknown | CVE List | 2.0.2-B20170511.1523 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMTOTOLINK CX-A3002RU - Remote Code ExecutionCVSS 6.8
An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.
Impact
Attackers can exploit this vulnerability to compromise system security and integrity.
Remediation
Apply the latest security patches and updates to address this vulnerability.
Source: ProjectDiscovery