PT-2024-25732 · Totolink · Totolink Ac1200 Wireless Router
Swind1Er
·
Published
2024-08-28
·
Updated
2024-08-31
·
CVE-2024-34195
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TOTOLINK AC1200 Wireless Router A3002R Firmware version 1.1.1-B20200824
Description
The issue is related to a Buffer Overflow vulnerability in the boa server program's CGI handling function
formWlEncrypt, due to a lack of length restriction on the wlan ssid field. This can lead to potential buffer overflow under specific circumstances, enabling arbitrary command execution or denial of service attacks. For instance, by invoking the formWlanRedirect function with specific parameters to alter wlan idx's value and subsequently invoking the formWlEncrypt function, an attacker can trigger buffer overflow.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Totolink Ac1200 Wireless Router