← Back to browse · API

CVE-2024-35397

Severity
HIGH
CVSS
8.8
EPSS
0.14976
Risk score
40.44
CISA KEV
No
PoC
No
Published
2024-05-28
Modified
2026-07-09
First seen
2026-08-07
Aliases
EUVD-2024-35314
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-35314

Description

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

References