Stack Overflow Vulnerability in TOTOLINK LR350 V9.3.5u.6369_B20220309
CVE-2024-35387

9.8CRITICAL

Key Information:

Vendor
TOTOLINK
Vendor
CVE Published:
24 May 2024

Summary

The TOTOLINK LR350 router version V9.3.5u.6369_B20220309 is vulnerable to a stack overflow that occurs through improper handling of the http_host parameter within the loginAuth function. This flaw may enable malicious actors to exploit the vulnerability, potentially leading to unauthorized access to the router's administrative interface and compromising network integrity. It is crucial for users of this device to apply patches or take necessary measures to safeguard against potential exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.