First published: Mon Jul 29 2024(Updated: )
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. Affected is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument langType leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272598 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Totolink A3600r Firmware | =4.1.2cu.5182_b20201102 | |
TOTOLink A3600R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7177 is classified as a critical vulnerability.
CVE-2024-7177 affects TOTOLINK A3600R firmware version 4.1.2cu.5182_B20201102.
To mitigate CVE-2024-7177, update the TOTOLINK A3600R firmware to a patched version that resolves the buffer overflow issue.
CVE-2024-7177 is a buffer overflow vulnerability that occurs in the setLanguageCfg function.
Yes, CVE-2024-7177 can potentially be exploited remotely through manipulation of the langType argument.