CVE-2024-37640: High severity totolink a3700r firmware vulnerability
Published Jun 14, 2024
·Updated
TOTOLINK A3700R V9.1.2u.616520211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.
Affected Software
3 affected components
Totolink A3700R Firmware
All of the following
Totolink A3700R Firmware=9.1.2u.6165_20211012
Totolink A3700R Firmware
Event History
Jun 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37640?
CVE-2024-37640 is classified as a high-severity vulnerability due to its potential to cause a stack overflow.
2
How do I fix CVE-2024-37640?
To fix CVE-2024-37640, users should update the TOTOLINK A3700R firmware to the latest version released by the vendor.
3
Which devices are affected by CVE-2024-37640?
CVE-2024-37640 specifically affects the TOTOLINK A3700R router with firmware version V9.1.2u.6165_20211012.
4
What is the impact of CVE-2024-37640?
The impact of CVE-2024-37640 includes potential remote code execution and denial of service due to stack overflow.
5
What component of TOTOLINK A3700R is vulnerable in CVE-2024-37640?
The vulnerable component in CVE-2024-37640 is the 'ssid5g' parameter in the 'setWiFiEasyGuestCfg' function.