{ "id": "CVE-2024-42743", "sourceIdentifier": "cve@mitre.org", "published": "2024-08-12T20:15:09.027", "lastModified": "2024-08-12T20:15:09.027", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenicated Attackers can send malicious packet to execute arbitary commands." } ], "metrics": {}, "references": [ { "url": "https://github.com/HouseFuzz/reports/blob/main/totolink/x5000r/setSyslogCfg/setSyslogCfg.md", "source": "cve@mitre.org" } ] }