First published: Tue May 28 2024(Updated: )
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRules
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink CP900L Firmware | ||
All of | ||
Totolink CP900L Firmware | =4.1.5cu.798_b20221228 | |
Totolink CP900L Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35400 has been classified with a high severity due to its potential for remote exploitation through a stack overflow.
To fix CVE-2024-35400, users should update the TOTOLINK CP900L firmware to a version that addresses this vulnerability.
CVE-2024-35400 affects the TOTOLINK CP900L router running firmware version 4.1.5cu.798_B20221228.
CVE-2024-35400 can be exploited through crafted requests that trigger a stack overflow in the SetPortForwardRules function.
Yes, successful exploitation of CVE-2024-35400 could lead to unauthorized access and control over the affected device.