PT-2024-26480 · Totolink · Totolink Cp900L

Published

2024-05-28

·

Updated

2024-11-07

·

CVE-2024-35400

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions TOTOLINK CP900L version 4.1.5cu.798 B20221228
Description A stack overflow issue was discovered via the desc parameter in the SetPortForwardRules function. This allows for potential exploitation.
Recommendations For TOTOLINK CP900L version 4.1.5cu.798 B20221228, consider restricting access to the SetPortForwardRules function until a patch is available. As a temporary workaround, avoid using the desc parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-35400

Affected Products

Totolink Cp900L