Totolink LR1200GB cstecgi.cgi setParentalRules stack-based overflow
CVE-2024-0574
Key Information:
Badges
Summary
A vulnerability in the Totolink LR1200GB router's firmware version 9.1.0u.6619_B20230130 has been identified, stemming from the setParentalRules function located in /cgi-bin/cstecgi.cgi. This issue arises due to improper handling of the sTime argument, resulting in a stack-based buffer overflow. Attackers can exploit this vulnerability remotely, which poses a significant risk to affected users. Despite early disclosure attempts to the vendor, there was no response, affirming the urgency for users to take precautionary measures.
Affected Version(s)
LR1200GB 9.1.0u.6619_B20230130
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved