PT-2024-25732 · Totolink · Totolink Ac1200 Wireless Router

Swind1Er

·

Published

2024-08-28

·

Updated

2024-08-31

·

CVE-2024-34195

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK AC1200 Wireless Router A3002R Firmware version 1.1.1-B20200824
Description The issue is related to a Buffer Overflow vulnerability in the boa server program's CGI handling function formWlEncrypt, due to a lack of length restriction on the wlan ssid field. This can lead to potential buffer overflow under specific circumstances, enabling arbitrary command execution or denial of service attacks. For instance, by invoking the formWlanRedirect function with specific parameters to alter wlan idx's value and subsequently invoking the formWlEncrypt function, an attacker can trigger buffer overflow.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-34195

Affected Products

Totolink Ac1200 Wireless Router