CVE-2024-10654: TOTOLINK LR350 formLoginAuth.htm authorization
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.3.5u.6698B20230810 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10654?
CVE-2024-10654 is classified as a critical vulnerability.
Which devices are affected by CVE-2024-10654?
CVE-2024-10654 affects TOTOLINK LR350 devices running firmware version up to 9.3.5u.6369.
How does CVE-2024-10654 impact the system?
CVE-2024-10654 allows for an authorization bypass through manipulation of the authCode argument in /formLoginAuth.htm.
How do I fix CVE-2024-10654?
To fix CVE-2024-10654, update your TOTOLINK LR350 device to the latest firmware version that addresses this vulnerability.
Is CVE-2024-10654 being actively exploited?
As of now, there are no public reports indicating active exploitation of CVE-2024-10654.