CVE-2024-33433: Totolink x2000r Firmware
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.
Affected products
- Totolink x2000r Firmware: before 1.0.0-b20231213.1013 (fixed in 1.0.0-b20231213.1013)
Published 2024-05-14. Last modified 2026-06-17.