← Vulnerability feed

Vulnerability record · CVE-2024-7907 · published 18 August 2024

CVE-2024-7907: Totolink x6000r firmware command injection vulnerability

TTotolink · X6000r Firmware

A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument rtLogServer leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

5.3 CVSS 4.0 Medium EPSS 6.2% · top 6.7% CWE-77 · Command injection
5.3CVSS 4.0 base score, v2 6.5
6.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument rtLogServer leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/BeaCox/IoT_vuln/tree/main/totolink/x6000R/setSyslogCfg_injection ExploitThird Party Advisory
https://vuldb.com/?ctiid.275033 Permissions RequiredVDB Entry
https://vuldb.com/?id.275033 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?submit.388424 Third Party AdvisoryVDB Entry

Track CVE-2024-7907 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-52053Totolink x6000r firmware command injection vulnerabilityTOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter…EPSS 4.4%9.8CVE-2024-52723Totolink x6000r firmware os command injection vulnerabilityIn TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can a…EPSS 1.0%9.8CVE-2024-1781Totolink x6000r firmware command injection vulnerabilityA vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg…EPSS 15%9.8CVE-2023-52038Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.EPSS 0.77%9.8CVE-2023-52039Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.EPSS 0.77%9.8CVE-2023-52040Totolink x6000r firmware command injection vulnerabilityAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.EPSS 0.85%9.8CVE-2023-52042Totolink x6000r firmware command injection vulnerabilityAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parame…EPSS 0.95%9.8CVE-2023-52041Totolink x6000r firmware vulnerabilityAn issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd progra…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2024-7907), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.