← Vulnerability feed

Vulnerability record · CVE-2024-24325 · published 30 January 2024

CVE-2024-24325: Totolink a3300r firmware os command injection vulnerability

TTotolink · A3300r Firmware

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.

9.8 CVSS 3.1 Critical EPSS 1.7% · top 23.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-24325 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-31178Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par…EPSS 1.4%9.8CVE-2026-31181Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p…EPSS 1.4%9.8CVE-2026-31175Totolink a3300r firmware command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param…EPSS 1.4%9.8CVE-2026-31177Totolink a3300r firmware os command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par…EPSS 1.4%9.8CVE-2026-31170Totolink a3300r firmware command injection vulnerabilityAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parame…EPSS 1.4%9.8CVE-2025-52046Totolink a3300r firmware command injection vulnerabilityTotolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and desc parame…EPSS 5.5%9.8CVE-2024-24326Totolink a3300r firmware os command injection vulnerabilityTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpR…EPSS 1.6%9.8CVE-2024-24327Totolink a3300r firmware os command injection vulnerabilityTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg fun…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2024-24325), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.