CVE-2024-7177: TOTOLINK A3600R cstecgi.cgi setLanguageCfg buffer overflow
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182B20201102. It has been classified as critical. Affected is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument langType leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272598 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7177?
CVE-2024-7177 is classified as a critical vulnerability.
What is the affected software for CVE-2024-7177?
CVE-2024-7177 affects TOTOLINK A3600R firmware version 4.1.2cu.5182_B20201102.
How do I fix CVE-2024-7177?
To mitigate CVE-2024-7177, update the TOTOLINK A3600R firmware to a patched version that resolves the buffer overflow issue.
What type of vulnerability is CVE-2024-7177?
CVE-2024-7177 is a buffer overflow vulnerability that occurs in the setLanguageCfg function.
Can CVE-2024-7177 be exploited remotely?
Yes, CVE-2024-7177 can potentially be exploited remotely through manipulation of the langType argument.