Buffer Overflow Vulnerability in TOTOLINK CA300-PoE Product
CVE-2024-7217

8.8HIGH

Key Information:

Vendor
Totolink
Vendor
CVE Published:
30 July 2024

Summary

A vulnerability has been identified in the TOTOLINK CA300-PoE version 6.2c.884 affecting the loginauth function located in the /cgi-bin/cstecgi.cgi file. This flaw allows for a potential buffer overflow due to improper handling of the password argument. As a consequence, attackers can exploit this vulnerability remotely to execute unauthorized actions. Despite early disclosure attempts to the vendor, there was no response, raising concerns about the exposure of users to potential attacks. Security experts recommend immediate attention to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.