First published: Tue May 14 2024(Updated: )
TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink LR350 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35099 is classified as a high severity vulnerability due to the potential for remote code execution via stack overflow.
To fix CVE-2024-35099, users should update the TOTOLINK LR350 to the latest firmware version provided by the manufacturer.
The risks associated with CVE-2024-35099 include unauthorized access and control over the device due to the stack overflow vulnerability.
CVE-2024-35099 affects the TOTOLINK LR350 router running firmware version V9.3.5u.6698_B20230810.
CVE-2024-35099 can be exploited through a crafted request that manipulates the password parameter in the loginAuth function.