CVE-2024-35387: Critical severity totolink lr350 firmware vulnerability
Published May 24, 2024
·Updated
TOTOLINK LR350 V9.3.5u.6369B20220309 was discovered to contain a stack overflow via the httphost parameter in the function loginAuth.
Affected Software
3 affected components
TOTOLINK LR350
All of the following
TOTOLINK Lr350 Firmware=9.3.5u.6369_b20220309
TOTOLINK LR350
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 24, 2024
CVE Published
via NVD·06:15 PM
Aug 2, 2024
Data Sourced
via MITRE·03:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35387?
CVE-2024-35387 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-35387?
To fix CVE-2024-35387, update the TOTOLINK LR350 firmware to the latest version provided by the vendor.
3
What kind of vulnerability is CVE-2024-35387?
CVE-2024-35387 is a stack overflow vulnerability that occurs through improper handling of the http_host parameter.
4
Which devices are affected by CVE-2024-35387?
CVE-2024-35387 specifically affects the TOTOLINK LR350 router running firmware version V9.3.5u.6369_B20220309.
5
What are the consequences of exploiting CVE-2024-35387?
Exploiting CVE-2024-35387 can lead to unauthorized access and control over the affected device, potentially compromising the network.