CVE-2024-37634: Critical severity totolink a3700r firmware vulnerability
Published Jun 13, 2024
·Updated
TOTOLINK A3700R V9.1.2u.616520211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.
Affected Software
3 affected components
Totolink A3700R Firmware
All of the following
Totolink A3700R Firmware=9.1.2u.6165_20211012
Totolink A3700R Firmware
Event History
Jun 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37634?
CVE-2024-37634 has been categorized as a high severity vulnerability due to its potential for remote exploitation.
2
How does CVE-2024-37634 affect TOTOLINK A3700R devices?
CVE-2024-37634 affects TOTOLINK A3700R devices by allowing a stack overflow through the 'ssid' parameter in the setWiFiEasyCfg function.
3
How do I fix CVE-2024-37634?
To fix CVE-2024-37634, users should update their TOTOLINK A3700R firmware to the latest version provided by the manufacturer.
4
Who is impacted by CVE-2024-37634?
Users of the TOTOLINK A3700R router with firmware version V9.1.2u.6165_20211012 are impacted by CVE-2024-37634.
5
What actions should I take if my device is vulnerable to CVE-2024-37634?
If your device is vulnerable to CVE-2024-37634, immediately update the firmware and consider disabling remote management features.