CVE-2024-54907
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 26, 2024
CWE ID 94
Summary
CVE-2024-54907 is a newly disclosed vulnerability affecting the TOTOLINK A3002R V4.0.0-B20230531.1404 firmware. This issue allows an unauthenticated attacker to execute arbitrary code remotely through a vulnerability in the /bin/boa component using formWsc. Successful exploitation could lead to complete control over the affected device, posing a significant risk to network security. Users are urged to update their firmware as soon as a patch becomes available to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.