cve/2024/CVE-2024-53333.md
2025-09-29 21:09:30 +02:00

19 lines
832 B
Markdown

### [CVE-2024-53333](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-53333)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=4.0.3c.7646_B20201211%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
### POC
#### Reference
- https://github.com/luckysmallbird/Totolink-EX200-Vulnerability-1/blob/main/README.md
#### Github
No PoCs found on GitHub currently.