First published: Fri May 24 2024(Updated: )
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink LR350 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35387 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2024-35387, update the TOTOLINK LR350 firmware to the latest version provided by the vendor.
CVE-2024-35387 is a stack overflow vulnerability that occurs through improper handling of the http_host parameter.
CVE-2024-35387 specifically affects the TOTOLINK LR350 router running firmware version V9.3.5u.6369_B20220309.
Exploiting CVE-2024-35387 can lead to unauthorized access and control over the affected device, potentially compromising the network.