Buffer Overflow Vulnerability in TOTOLINK A3600R Firmware
CVE-2024-7182
Key Information:
Badges
Summary
A critical buffer overflow vulnerability has been identified in the TOTOLINK A3600R router firmware version 4.1.2cu.5182_B20201102, specifically affecting the setUpgradeFW function within the cstecgi.cgi file. This vulnerability arises from improper handling of the FileName argument, allowing an attacker to exploit it remotely. Given the nature of this vulnerability, it could lead to unauthorized access or control over affected devices. Despite attempts to notify the vendor prior to disclosure, there has been no response. The exploitation of this vulnerability poses a significant risk to the security of affected systems and needs immediate attention.
Affected Version(s)
A3600R 4.1.2cu.5182_B20201102
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved