CVE-2024-37635: Critical severity totolink a3700r firmware vulnerability
Published Jun 13, 2024
·Updated
TOTOLINK A3700R V9.1.2u.616520211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg
Affected Software
2 affected components
All of the following
Totolink A3700R Firmware=9.1.2u.6165_20211012
Totolink A3700R Firmware
Event History
Jun 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-37635?
CVE-2024-37635 has been classified as a high severity vulnerability due to its potential for exploitation through stack overflow.
2
How do I fix CVE-2024-37635?
To fix CVE-2024-37635, update the TOTOLINK A3700R firmware to the latest version provided by the vendor.
3
What is the impact of CVE-2024-37635?
The impact of CVE-2024-37635 includes the possibility of remote code execution due to a stack overflow in the setWiFiBasicCfg function.
4
Is my device vulnerable to CVE-2024-37635?
Devices running the TOTOLINK A3700R firmware version 9.1.2u.6165_20211012 are vulnerable to CVE-2024-37635.
5
How can I determine if I am running the affected firmware for CVE-2024-37635?
Check the firmware version in your TOTOLINK A3700R device settings to see if it matches version 9.1.2u.6165_20211012, which is affected by CVE-2024-37635.