PT-2022-12028 · Totolink · Totolink A720R+2
Published
2022-02-04
·
Updated
2023-08-08
·
CVE-2021-44246
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Totolink A3100R version 4.1.2cu.5050 B20200504
Totolink A830R version 5.9c.4729 B20191112
Totolink A720R version 4.1.5cu.470 B20200911
Description
A stack overflow was discovered in the
setNoticeCfg function, allowing attackers to cause a Denial of Service (DoS) via the IpTo parameter.Recommendations
For Totolink A3100R version 4.1.2cu.5050 B20200504, consider disabling the
setNoticeCfg function to prevent exploitation.
For Totolink A830R version 5.9c.4729 B20191112, restrict access to the IpTo parameter in the affected API endpoint until a fix is available.
For Totolink A720R version 4.1.5cu.470 B20200911, avoid using the IpTo parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink A3100R
Totolink A720R
Totolink A830R