CVE-2024-54907

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 26, 2024
CWE ID 94

Summary

CVE-2024-54907 is a newly disclosed vulnerability affecting the TOTOLINK A3002R V4.0.0-B20230531.1404 firmware. This issue allows an unauthenticated attacker to execute arbitrary code remotely through a vulnerability in the /bin/boa component using formWsc. Successful exploitation could lead to complete control over the affected device, posing a significant risk to network security. Users are urged to update their firmware as soon as a patch becomes available to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share