216.73.216.197

CVE-2024-35397

· Published 28/05/2024 15:15 · Modified 28/05/2024 17:11

Labels: CVE-2024-35397 2024-05-28CVE-2024-35397[email protected]

Essential information

Published
28/05/2024 15:15
Modified
28/05/2024 17:11
Author
Creator
CISA KEV
No
CWE

Description

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References