CVE-2024-57021
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 15, 2025
Updated: Jan 16, 2025
CWE ID 78
Summary
CVE-2024-57021 represents a significant cybersecurity vulnerability affecting the TOTOLINK X5000R V9.1.0cu.2350_B20230313 firmware. This issue is caused by an OS command injection flaw that can be exploited through the "eHour" parameter in the setWiFiScheduleCfg function. An attacker could potentially gain unauthorized control over the device by injecting malicious commands, resulting in serious security implications. Users are advised to update their firmware as soon as a patch becomes available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.