← Back to CVE List

CVE-2024-35397

Published: 2024-05-28T15:15Z
Last Modified: 2025-04-03T15:45Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt