CVE-2024-9001

MEDIUM EXPLOITED

TOTOLINK T10 4.1.8cu.5207 - OS Command Injection via setTracerouteCfg

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-9001 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.278152
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.278152
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.406140
Product product
https://www.totolink.net/

Scores

CVSS v3 6.3
EPSS 0.0077
EPSS Percentile 73.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

VulnCheck KEV 2025-07-13
CWE
CWE-78
Status published
Products (1)
totolink/t10_firmware 4.1.8cu.5207
Published Sep 19, 2024
Tracked Since Feb 18, 2026