Stack Overflow Vulnerability in TOTOLINK Router Firmware
CVE-2022-29641

7.5HIGH

Key Information:

Vendor
Totolink
Vendor
CVE Published:
18 May 2022

Summary

The TOTOLINK A3100R router firmware versions V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 contain a stack overflow vulnerability caused by improper handling of the startTime and endTime parameters within the setParentalRules function. This flaw enables remote attackers to send specially crafted POST requests that can result in a Denial of Service (DoS), disrupting normal operations of the device.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.