CVE-2024-42745 | TOTOLINK X5000r 9.1.0cu.2350_b20230313 /cgi-bin/cstecgi.cgi setUPnPCfg os command injection
A vulnerability was found in TOTOLINK X5000r 9.1.0cu.2350_b20230313. It has been declared as critical. This vulnerability affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to os command injection.
This vulnerability was named CVE-2024-42745. Access to the local network is required for this attack to succeed. There is no exploit available.