CVE-2024-34196: Buffer Overflow
Totolink AC1200 Wireless Dual Band Gigabit Router A3002RUV3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of the "vwlanidx" field via "formMultiAP". This can lead to a stack overflow through the "formWlEncrypt" CGI function by constructing malicious HTTP requests and passing a WLAN SSID value exceeding the expected length, potentially resulting in command execution or denial of service attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34196?
CVE-2024-34196 is classified as a high-severity vulnerability due to its potential to cause a buffer overflow.
How do I fix CVE-2024-34196?
To fix CVE-2024-34196, users should update the firmware of the Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU to a patched version.
What does CVE-2024-34196 affect?
CVE-2024-34196 specifically affects the Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU running firmware version V3.0.0-B20230809.1615.
What could happen if CVE-2024-34196 is exploited?
If exploited, CVE-2024-34196 could result in a stack overflow that allows attackers to execute arbitrary code.
What is the attack vector for CVE-2024-34196?
The attack vector for CVE-2024-34196 involves manipulating the "vwlan_idx" field through the "formMultiAP" within the "boa" program.