CVE-2024-34195: Buffer Overflow

Published Aug 28, 2024
·
Updated

TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlanssid field. This oversight leads to potential buffer overflow under specific circumstances. For instance, by invoking the formWlanRedirect function with specific parameters to alter wlanidx's value and subsequently invoking the formWlEncrypt function, an attacker can trigger buffer overflow, enabling arbitrary command execution or denial of service attacks.

Affected Software

2 affected components
All of the following
TOTOLINK A3002R Firmware=1.1.1-b20200824
TOTOLINK A3002R

Event History

Aug 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-34195?

CVE-2024-34195 is classified as a high severity vulnerability due to the potential for buffer overflow leading to remote code execution.

2

How do I fix CVE-2024-34195?

To fix CVE-2024-34195, update the TOTOLINK AC1200 Wireless Router A3002R to the latest firmware version released after 1.1.1-B20200824.

3

What systems are affected by CVE-2024-34195?

CVE-2024-34195 affects the TOTOLINK AC1200 Wireless Router A3002R running firmware version 1.1.1-B20200824.

4

Can CVE-2024-34195 be exploited remotely?

Yes, CVE-2024-34195 can be exploited remotely due to vulnerabilities in the boa server program's CGI handling.

5

What are the risks of CVE-2024-34195?

The risks of CVE-2024-34195 include unauthorized access and potential control of the affected wireless router.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203