PT-2024-27107 · Totolink · Totolink Ac1200 Wireless Dual Band Gigabit Router

Swind1Er

·

Published

2024-06-11

·

Updated

2025-06-04

·

CVE-2024-36650

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware version A3100R V4.1.2cu.5247 B20211129
Description The issue arises from the lack of input validation in the setNoticeCfg function, specifically with the NoticeUrl variable. This omission can lead to a buffer overflow, enabling attackers to craft malicious requests. As a result, this can cause a denial-of-service attack by constructing malicious HTTP or MQTT requests.
Recommendations For TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware version A3100R V4.1.2cu.5247 B20211129, as a temporary workaround, consider restricting access to the /lib/cste modules/system.so file to minimize the risk of exploitation. Additionally, avoid using the NoticeUrl variable in the setNoticeCfg function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-36650

Affected Products

Totolink Ac1200 Wireless Dual Band Gigabit Router