Totolink · Totolink N200Re · CVE-2024-0999
**Name of the Vulnerable Software and Affected Versions**
Totolink N200RE version 9.3.5u.6139 B20201216
**Description**
A critical issue affects the `setParentalRules` function of the `/cgi-bin/cstecgi.cgi` file, where manipulation of the `eTime` argument leads to a stack-based buffer overflow. This can be initiated remotely, potentially impacting the confidentiality, integrity, and availability of protected information. The issue may also involve the `week` and `sTime` parameters. An exploit has been disclosed publicly.
**Recommendations**
For Totolink N200RE version 9.3.5u.6139 B20201216, as a temporary workaround, consider disabling the `setParentalRules` function until a patch is available. Restrict access to the `/cgi-bin/cstecgi.cgi` file to minimize the risk of exploitation. Avoid using the `eTime`, `week`, and `sTime` parameters in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.