CVE-2024-37631: High severity totolink a3700r firmware vulnerability
Published Jun 13, 2024
·Updated
TOTOLINK A3700R V9.1.2u.616520211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.
Affected Software
3 affected components
Totolink A3700R Firmware
All of the following
Totolink A3700R Firmware=9.1.2u.6165_20211012
Totolink A3700R Firmware
Event History
Jun 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37631?
CVE-2024-37631 is categorized as a high severity vulnerability due to its potential to cause a stack overflow.
2
How do I fix CVE-2024-37631?
To fix CVE-2024-37631, update the TOTOLINK A3700R to the latest firmware version provided by the manufacturer.
3
What is affected by CVE-2024-37631?
CVE-2024-37631 affects the TOTOLINK A3700R with firmware version V9.1.2u.6165_20211012.
4
How does CVE-2024-37631 work?
CVE-2024-37631 exploits a stack overflow vulnerability through the File parameter in the UploadCustomModule function.
5
Who is responsible for addressing CVE-2024-37631?
It is the responsibility of TOTOLINK to provide updates and mitigations for CVE-2024-37631 to their users.