CVE-2024-7172: TOTOLINK A3600R getSaveConfig buffer overflow
A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182B20201102. Affected by this vulnerability is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument httphost leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272593 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7172?
CVE-2024-7172 is classified as a critical vulnerability.
How do I fix CVE-2024-7172?
To fix CVE-2024-7172, update the TOTOLINK A3600R firmware to the latest version beyond 4.1.2cu.5182_B20201102.
What is the impact of CVE-2024-7172?
CVE-2024-7172 can lead to a buffer overflow due to improper handling of the http_host argument.
Which versions are affected by CVE-2024-7172?
CVE-2024-7172 affects TOTOLINK A3600R firmware version 4.1.2cu.5182_B20201102.
How is CVE-2024-7172 exploited?
CVE-2024-7172 can be exploited by manipulating the http_host argument in the getSaveConfig function.