ID

VAR-202405-0384


CVE

CVE-2024-32350


TITLE

TOTOLINK X5000R ipsecPsk parameter code execution vulnerability

Trust: 0.6

sources: CNVD: CNVD-2024-40409

DESCRIPTION

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary. TOTOLINK X5000R is a router of China's TOTOLINK Electronics. TOTOLINK X5000R has a code execution vulnerability, which is caused by the ipsecPsk parameter of cstecgi.cgi failing to properly filter special elements of the constructed code segment. Attackers can exploit this vulnerability to cause arbitrary code execution

Trust: 1.44

sources: NVD: CVE-2024-32350 // CNVD: CNVD-2024-40409

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-40409

AFFECTED PRODUCTS

vendor:totolinkmodel:x5000r v9.1.0cu.2350 b20230313scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2024-40409

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-32350
value: HIGH

Trust: 1.0

CNVD: CNVD-2024-40409
value: HIGH

Trust: 0.6

CNVD: CNVD-2024-40409
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-32350
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2024-40409 // NVD: CVE-2024-32350

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.0

sources: NVD: CVE-2024-32350

EXTERNAL IDS

db:NVDid:CVE-2024-32350

Trust: 1.6

db:CNVDid:CNVD-2024-40409

Trust: 0.6

sources: CNVD: CNVD-2024-40409 // NVD: CVE-2024-32350

REFERENCES

url:https://github.com/1s1and123/vulnerabilities/blob/main/device/totolink/x5000r/totolink_x5000r_rce.md

Trust: 1.0

url:https://www.totolink.net/

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-32350

Trust: 0.6

sources: CNVD: CNVD-2024-40409 // NVD: CVE-2024-32350

SOURCES

db:CNVDid:CNVD-2024-40409
db:NVDid:CVE-2024-32350

LAST UPDATE DATE

2024-10-13T23:20:50.281000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-40409date:2024-10-11T00:00:00
db:NVDid:CVE-2024-32350date:2024-08-20T17:35:06.123

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-40409date:2024-10-11T00:00:00
db:NVDid:CVE-2024-32350date:2024-05-14T16:17:02.543