CVE-2022-44257: Buffer Overflow
TOTOLINK LR350 V9.3.5u.6369B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44257?
CVE-2022-44257 is a vulnerability in TOTOLINK LR350 V9.3.5u.6369_B20220309 firmware that allows a post-authentication buffer overflow through the pppoeUser parameter in the setOpModeCfg function.
What is the severity of CVE-2022-44257?
The severity of CVE-2022-44257 is high with a CVSS score of 8.8.
How does CVE-2022-44257 affect TOTOLINK LR350?
CVE-2022-44257 affects TOTOLINK LR350 V9.3.5u.6369_B20220309 firmware by allowing a post-authentication buffer overflow.
How can I mitigate CVE-2022-44257?
To mitigate CVE-2022-44257, it is recommended to update TOTOLINK LR350 firmware to a version that has addressed the vulnerability.
Where can I find more information about CVE-2022-44257?
You can find more information about CVE-2022-44257 at the following reference link: [Reference Link](https://brief-nymphea-813.notion.site/LR350-bof-setOpModeCfg-9dc3504e403f445b85d5db09176ac406)