CVE-2024-0942

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 26, 2024
Updated: May 17, 2024
CWE ID 613

Summary

CVE-2024-0942 represents a newly-disclosed vulnerability affecting the Totolink N200RE V5 9.3.5u.6255_B20211224 firmware. This issue is classified as problematic and impacts an unidentified function within the /cgi-bin/cstecgi.cgi file. Manipulation results in session expiration, allowing for potential remote attacks with a high degree of complexity. The exploitability is considered difficult, but the exploit has been made public, increasing the risk of exploitation. VDB-252186 serves as the identifier for this vulnerability, and attempts to contact the vendor for a response have been unsuccessful.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share