PT-2022-19746 · Totolink · Totolink A3100R

Hijin0925

·

Published

2022-05-18

·

Updated

2022-05-26

·

CVE-2022-29642

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A3100R versions V4.1.2cu.5050 B20200504 through V4.1.2cu.5247 B20211129
Description A stack overflow issue was discovered via the url parameter in the setUrlFilterRules() function, allowing attackers to cause a Denial of Service (DoS) via a crafted POST request to the /api endpoint, although the exact endpoint is not specified.
Recommendations For versions V4.1.2cu.5050 B20200504 through V4.1.2cu.5247 B20211129, consider disabling the setUrlFilterRules() function as a temporary workaround until a patch is available. Restrict access to the url parameter in the affected function to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29642

Affected Products

Totolink A3100R