S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated Mar 6, 2025

CVE-2024-51228 Scanner

CVE-2024-51228 Scanner - Remote Code Execution vulnerability in TOTOLINK CX-A3002RU

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-51228
6.8
CVSSmedium
Exploitable from an adjacent network · requires high privileges.

An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.

Attack Vector
Adjacent
Privileges Req.
High
User Interaction
None
Affected
n/aby n/a
n/a
a3002ru_firmwareby totolink
1.0.4-B20171106.1512
n150rt_firmwareby totolink
2.1.6-B20171121.1002
n300rt_firmwareby totolink
2.1.6-B20170724.1420
Updated Aug 22, 2026View on NVD →
Detail

The TOTOLINK CX-A3002RU is a wireless router widely used in both home and office settings. It is favored for its robust performance and affordable price, making it a popular choice among users seeking reliable internet connectivity. With features like wireless AC support and multiple LAN ports, the router is designed to facilitate seamless internet access and sharing. Its ease of use and setup makes it accessible even for users with limited technical expertise. TOTOLINK products are often targeted towards consumers looking for budget-friendly networking solutions. However, their widespread usage also makes them susceptible to security vulnerabilities if not updated regularly.

Remote Code Execution (RCE) is a critical security vulnerability that allows an attacker to remotely execute commands on a device. This vulnerability in TOTOLINK CX-A3002RU affects specific versions, enabling unauthorized users to exploit system functionalities via crafted HTTP requests. RCE exploits can be highly damaging, as they grant attackers control over affected systems, potentially leading to data theft or further exploitation of network resources. Such vulnerabilities highlight the dangers of default configurations and the necessity for regular security updates. Users of vulnerable devices are at risk until patches or mitigation strategies are effectively deployed.

The vulnerability in TOTOLINK CX-A3002RU exists in the /boafrm/formSysCmd component. By sending a specially crafted POST request to this endpoint, remote attackers can exploit the system’s command execution functionality. The vulnerable parameter, sysCmd, can be manipulated to execute arbitrary commands, such as the command to sleep the system for a specified duration. Successful exploitation relies on specific server responses, including status codes and server type verification. This technical entry point creates an opportunity for attackers to perform unauthorized actions on the target system.

When exploited, this RCE vulnerability can lead to severe consequences, including complete system compromise. Attackers can execute arbitrary code, giving them control over the router’s operations and data access. This can result in unauthorized network monitoring, data exfiltration, or the deployment of malware. Furthermore, compromised devices can be leveraged for broader network attacks, such as turning them into part of a botnet. The resulting impact extends beyond the individual device, posing significant security risks to connected systems.

REFERENCES

Solution Advice
  • Ensure that your router firmware is updated to the latest version provided by the manufacturer.
  • Restrict access to administrative interfaces to trusted IP addresses and implement network segregation where possible.
  • Regularly monitor network traffic for signs of unusual activity or exploitation attempts.
  • Disable unnecessary services on devices and adhere to the principle of least privilege.
  • Employ intrusion detection systems to identify and mitigate exploitation attempts in real time.
  • Consider replacing hardware that no longer receives security updates from the manufacturer.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.