CVE-2024-0299
CVE-2024-0299 is a high-severity vulnerability in Totolink N200re Firmware with a CVSS 3.x base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: High (CVSS 3.x base score 7.3)
- CVSS v2: 7.5
- EPSS exploit prediction: 4% (89th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-16095
- Weakness: CWE-78
- Affected product: Totolink N200re Firmware
- Published:
- Last modified:
Description
A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249865 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Frequently asked questions
- What is CVE-2024-0299?
- A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249865 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
- How severe is CVE-2024-0299?
- CVE-2024-0299 has a CVSS 3.x base score of 7.3, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2024-0299 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (89th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-0299?
- CVE-2024-0299 affects Totolink N200re Firmware. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-0299?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2024-0299 have an EU (EUVD) identifier?
- Yes. CVE-2024-0299 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-16095.
- When was CVE-2024-0299 published?
- CVE-2024-0299 was published on 2024-01-08 and last updated on 2026-06-17.
References
- https://github.com/jylsec/vuldb/blob/main/TOTOLINK/N200RE/setTracerouteCfg/README.md
- https://vuldb.com/?ctiid.249865
- https://vuldb.com/?id.249865
Affected products (1)
- cpe:2.3:o:totolink:n200re_firmware:9.3.5u.6139_b20201216:*:*:*:*:*:*:*
More vulnerabilities in Totolink N200re Firmware
- CVE-2019-19825 — Critical (CVSS 9.8): On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an…
- CVE-2025-55895 — Critical (CVSS 9.1): TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to…
- CVE-2019-19824 — High (CVSS 8.8): On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the…
- CVE-2019-19823 — High (CVSS 7.5): A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext…
- CVE-2019-19822 — High (CVSS 7.5): A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote…
- CVE-2024-0298 — High (CVSS 7.3): A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the…
All CVEs affecting Totolink N200re Firmware →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…
- CVE-2026-48362 — Critical (CVSS 10.0): ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…
- CVE-2026-16812 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-6516 — Critical (CVSS 10.0): Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to…
- CVE-2026-46339 — Critical (CVSS 10.0): 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect…
- CVE-2026-59726 — Critical (CVSS 10.0): Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment…