CVE-2022-37840: Buffer Overflow
Published Sep 6, 2022
·Updated
In TOTOLINK A860R V4.1.2cu.5182B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability.
Affected Software
2 affected components
TOTOLINK A860r Firmware=4.1.2cu.5182_b20201027
TOTOLINK A860R
Event History
Sep 6, 2022
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-37840?
CVE-2022-37840 is classified as a high severity vulnerability due to its potential for exploitation through a buffer overflow.
2
How do I fix CVE-2022-37840?
To mitigate CVE-2022-37840, users should update the TOTOLINK A860R firmware to a non-vulnerable version.
3
What types of attacks are possible with CVE-2022-37840?
CVE-2022-37840 may allow attackers to execute arbitrary code or crash the device due to the buffer overflow.
4
Which versions of TOTOLINK A860R are affected by CVE-2022-37840?
CVE-2022-37840 affects TOTOLINK A860R firmware version 4.1.2cu.5182_b20201027.
5
Is CVE-2022-37840 easy to exploit?
Yes, CVE-2022-37840 can be easily exploited if the attacker has access to the affected firmware version.