CVE-2024-35399: High severity TOTOLINK CP900L vulnerability
Published May 28, 2024
·Updated
TOTOLINK CP900L v4.1.5cu.798B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth
Affected Software
3 affected components
TOTOLINK CP900L
All of the following
TOTOLINK Cp900l Firmware=4.1.5cu.798_b20221228
TOTOLINK CP900L
Event History
May 28, 2024
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35399?
CVE-2024-35399 is classified as a high severity vulnerability due to the potential for remote code execution via stack overflow.
2
How do I fix CVE-2024-35399?
To fix CVE-2024-35399, update the TOTOLINK CP900L firmware to the latest version provided by the vendor.
3
What is the affected version of TOTOLINK CP900L for CVE-2024-35399?
CVE-2024-35399 affects TOTOLINK CP900L firmware version 4.1.5cu.798_B20221228.
4
What types of attacks can exploit CVE-2024-35399?
CVE-2024-35399 can be exploited through crafted authentication requests, leading to a stack overflow.
5
Is there a mitigation for CVE-2024-35399 if firmware cannot be updated?
If firmware cannot be updated, mitigate the risk of CVE-2024-35399 by restricting access to the device's management interface.