PT-2022-23385 · Totolink · Totolink A3700R
Published
2022-08-25
·
Updated
2025-06-08
·
CVE-2022-36462
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TOTOLINK A3700R version 9.1.2u.6134 B20201202
Description
A stack overflow issue was discovered in the setLanguageCfg function via the
lang parameter.Recommendations
For version 9.1.2u.6134 B20201202, avoid using the
lang parameter in the setLanguageCfg function until a fix is available. As a temporary workaround, consider restricting access to the setLanguageCfg function to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Totolink A3700R