CVE-2024-34195: Buffer Overflow
TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlanssid field. This oversight leads to potential buffer overflow under specific circumstances. For instance, by invoking the formWlanRedirect function with specific parameters to alter wlanidx's value and subsequently invoking the formWlEncrypt function, an attacker can trigger buffer overflow, enabling arbitrary command execution or denial of service attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34195?
CVE-2024-34195 is classified as a high severity vulnerability due to the potential for buffer overflow leading to remote code execution.
How do I fix CVE-2024-34195?
To fix CVE-2024-34195, update the TOTOLINK AC1200 Wireless Router A3002R to the latest firmware version released after 1.1.1-B20200824.
What systems are affected by CVE-2024-34195?
CVE-2024-34195 affects the TOTOLINK AC1200 Wireless Router A3002R running firmware version 1.1.1-B20200824.
Can CVE-2024-34195 be exploited remotely?
Yes, CVE-2024-34195 can be exploited remotely due to vulnerabilities in the boa server program's CGI handling.
What are the risks of CVE-2024-34195?
The risks of CVE-2024-34195 include unauthorized access and potential control of the affected wireless router.