First published: Tue May 28 2024(Updated: )
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink CP900L Firmware | ||
All of | ||
Totolink CP900L Firmware | =4.1.5cu.798_b20221228 | |
Totolink CP900L Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35399 is classified as a high severity vulnerability due to the potential for remote code execution via stack overflow.
To fix CVE-2024-35399, update the TOTOLINK CP900L firmware to the latest version provided by the vendor.
CVE-2024-35399 affects TOTOLINK CP900L firmware version 4.1.5cu.798_B20221228.
CVE-2024-35399 can be exploited through crafted authentication requests, leading to a stack overflow.
If firmware cannot be updated, mitigate the risk of CVE-2024-35399 by restricting access to the device's management interface.