CVE-2024-42520: Buffer Overflow
Published Aug 12, 2024
·Updated
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.
Affected Software
2 affected components
All of the following
TOTOLINK A3002R Firmware=4.0.0-b20230531.1404
TOTOLINK A3002R
Event History
Aug 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-42520?
CVE-2024-42520 is classified as a buffer overflow vulnerability which can lead to potential remote code execution.
2
How do I fix CVE-2024-42520?
To mitigate CVE-2024-42520, it is recommended to upgrade to a patched version of the Totolink A3002R firmware that addresses this vulnerability.
3
Which versions are affected by CVE-2024-42520?
CVE-2024-42520 specifically affects Totolink A3002R firmware version 4.0.0-B20230531.1404.
4
What component is vulnerable in CVE-2024-42520?
The buffer overflow vulnerability in CVE-2024-42520 is found in the /bin/boa component via formParentControl.
5
Can CVE-2024-42520 be exploited remotely?
Yes, CVE-2024-42520 may be remotely exploitable due to the nature of the buffer overflow in the web interface.