PT-2024-38177 · Totolink · Totolink Ca300-Poe

Yhryhryhr_Miemie

·

Published

2024-07-30

·

Updated

2024-08-06

·

CVE-2024-7217

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK CA300-PoE version 6.2c.884
Description A critical issue affects the loginauth function of the /cgi-bin/cstecgi.cgi file, where manipulation of the password argument leads to buffer overflow. This can be initiated remotely. The issue has been publicly disclosed and may be exploited. The vendor was contacted about this issue but did not respond.
Recommendations For TOTOLINK CA300-PoE version 6.2c.884, as a temporary workaround, consider restricting access to the /cgi-bin/cstecgi.cgi file to minimize the risk of exploitation. Avoid using the password argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-7217

Affected Products

Totolink Ca300-Poe