CVE-2024-36650: Buffer Overflow
TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247B20211129, in the cgi function setNoticeCfg of the file /lib/cstemodules/system.so, the length of the user input string NoticeUrl is not checked. This can lead to a buffer overflow, allowing attackers to construct malicious HTTP or MQTT requests to cause a denial-of-service attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36650?
CVE-2024-36650 is classified as a critical vulnerability due to the potential for a buffer overflow leading to remote code execution.
How do I fix CVE-2024-36650?
To fix CVE-2024-36650, update the firmware of the TOTOLINK AC1200 Wireless Dual Band Gigabit Router to the latest version available from the manufacturer.
What are the potential impacts of CVE-2024-36650?
CVE-2024-36650 can allow attackers to exploit the buffer overflow vulnerability to execute arbitrary code on the affected router.
Is my router vulnerable if it runs the affected firmware mentioned in CVE-2024-36650?
Yes, routers running the specified firmware version A3100R V4.1.2cu.5247_B20211129 are vulnerable to CVE-2024-36650.
What should I do if I am unable to update the firmware for CVE-2024-36650?
If you cannot update the firmware, it is advised to disconnect the router from the internet to mitigate the risk associated with CVE-2024-36650.