CVE-2022-44258: Buffer Overflow
TOTOLINK LR350 V9.3.5u.6369B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44258?
CVE-2022-44258 is a vulnerability in TOTOLINK LR350 V9.3.5u.6369_B20220309 that allows for a post-authentication buffer overflow via the 'command' parameter in the setTracerouteCfg function.
What is the severity of CVE-2022-44258?
CVE-2022-44258 has a severity score of 8.8, which is considered high.
How does CVE-2022-44258 affect TOTOLINK LR350 Firmware version 9.3.5u.6369_b20220309?
CVE-2022-44258 affects TOTOLINK LR350 Firmware version 9.3.5u.6369_b20220309 by allowing a post-authentication buffer overflow through the 'command' parameter in the setTracerouteCfg function.
How can I fix CVE-2022-44258?
Currently, there is no known fix or patch available for CVE-2022-44258. It is recommended to monitor the vendor's security advisories for updates or mitigations.
What is CWE-119 and CWE-787?
CWE-119 refers to Improper Restriction of Operations within the Bounds of a Memory Buffer, while CWE-787 refers to Out-of-bounds Write.