Stack Overflow Vulnerability in TOTOLINK CP900L
CVE-2024-35399
8.8HIGH
Summary
The TOTOLINK CP900L is susceptible to a stack overflow due to an issue in the loginAuth function. This vulnerability occurs when the password parameter is processed, potentially allowing an attacker to exploit the system. An attacker can leverage this weakness to execute arbitrary code or cause a denial of service, therefore compromising the integrity and availability of the device. It is crucial for users of the affected product to assess their security strategies and apply any available mitigations.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published