CVE-2024-34308: High severity totolink lr350 firmware vulnerability
Published May 14, 2024
·Updated
TOTOLINK LR350 V9.3.5u.6369B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.
Affected Software
3 affected components
TOTOLINK LR350
All of the following
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:38 PM
Aug 2, 2024
Data Sourced
via MITRE·02:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-34308?
CVE-2024-34308 is rated as critical due to its potential to cause a stack overflow.
2
How do I fix CVE-2024-34308?
To fix CVE-2024-34308, update the TOTOLINK LR350 to the latest firmware version released by the manufacturer.
3
What impact does CVE-2024-34308 have on TOTOLINK LR350 devices?
CVE-2024-34308 can lead to remote code execution due to the stack overflow vulnerability in the password parameter.
4
Is CVE-2024-34308 being actively exploited?
As of the latest reports, there are indications that CVE-2024-34308 is being actively exploited in the wild.
5
What versions of TOTOLINK LR350 are affected by CVE-2024-34308?
CVE-2024-34308 affects TOTOLINK LR350 devices running version V9.3.5u.6369_B20220309.