PT-2023-9638 · Totolink · Totolink Lr350

·

CVE-2024-10654

·

Published

2023-09-07

·

Updated

2024-11-05

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK LR350 versions up to 9.3.5u.6369
Description A critical issue is related to the authorization procedure, specifically with the handling of the authCode parameter. This can allow a remote attacker to bypass security restrictions. The vulnerability affects an unknown functionality of the file /formLoginAuth.htm. Manipulating the authCode argument with the input 1 leads to authorization bypass. The attack can be launched remotely.
Recommendations For TOTOLINK LR350 versions up to 9.3.5u.6369, upgrade to version 9.3.5u.6698 B20230810 to address this issue. As a temporary workaround, consider restricting access to the /formLoginAuth.htm file and avoiding manipulation of the authCode parameter until the upgrade is applied.

Exploit

Fix

Incorrect Privilege Assignment

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08968
CVE-2024-10654

Affected Products

Totolink Lr350