CVE-2022-36466: High severity totolink a3700r firmware vulnerability
TOTOLINK A3700R V9.1.2u.6134B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36466?
CVE-2022-36466 is a vulnerability discovered in TOTOLINK A3700R V9.1.2u.6134_B20201202 firmware that allows for a stack overflow through the ip parameter in the setDiagnosisCfg function.
What is the severity of CVE-2022-36466?
CVE-2022-36466 has a severity value of 7.8, which is considered high.
How does CVE-2022-36466 affect TOTOLINK A3700R?
CVE-2022-36466 affects TOTOLINK A3700R V9.1.2u.6134_B20201202 firmware by causing a stack overflow when the ip parameter is used in the setDiagnosisCfg function.
Is TOTOLINK A3700R V9.1.2u.6134_B20201202 firmware vulnerable to CVE-2022-36466?
Yes, TOTOLINK A3700R V9.1.2u.6134_B20201202 firmware is vulnerable to CVE-2022-36466.
How can I fix the CVE-2022-36466 vulnerability in TOTOLINK A3700R?
To fix the CVE-2022-36466 vulnerability in TOTOLINK A3700R, it is recommended to update the firmware to a non-vulnerable version provided by the manufacturer.