Buffer Overflow Vulnerability in TOTOLINK A3300R
CVE-2024-7331
8.8HIGH
What is CVE-2024-7331?
A critical buffer overflow vulnerability has been identified in the TOTOLINK A3300R router within the UploadCustomModule function located at /cgi-bin/cstecgi.cgi. This vulnerability stems from improper handling of input parameters, where the argument 'File' can be manipulated, allowing for remote code execution through a buffer overflow exploit. The flaw can be exploited without user authentication, putting affected devices at significant risk. The vendor has been notified about the issue but has yet to respond or provide a fix. Users of the affected versions are advised to take precautionary measures to secure their devices.
Affected Version(s)
A3300R 17.0.0cu.557_B20221024
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
- 👾
Exploit known to exist
Credit
yhryhryhr_miemie (VulDB User)
