CVE-2024-34204: Totolink CP450 Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.

Affected products

  • Totolink CP450 Firmware: version 4.1.0cu.747_b20191224 only

Published 2024-05-14. Last modified 2026-06-17.