CVE-2024-35099: Critical severity totolink lr350 firmware vulnerability
Published May 14, 2024
·Updated
TOTOLINK LR350 V9.3.5u.6698B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
Affected Software
3 affected components
TOTOLINK LR350
All of the following
TOTOLINK Lr350 Firmware=9.3.5u.6698_b20230810
TOTOLINK LR350
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:39 PM
Aug 20, 2024
Data Sourced
via MITRE·04:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35099?
CVE-2024-35099 is classified as a high severity vulnerability due to the potential for remote code execution via stack overflow.
2
How do I fix CVE-2024-35099?
To fix CVE-2024-35099, users should update the TOTOLINK LR350 to the latest firmware version provided by the manufacturer.
3
What are the risks associated with CVE-2024-35099?
The risks associated with CVE-2024-35099 include unauthorized access and control over the device due to the stack overflow vulnerability.
4
What systems are affected by CVE-2024-35099?
CVE-2024-35099 affects the TOTOLINK LR350 router running firmware version V9.3.5u.6698_B20230810.
5
How is CVE-2024-35099 exploited?
CVE-2024-35099 can be exploited through a crafted request that manipulates the password parameter in the loginAuth function.