CVE-2024-7179: TOTOLINK A3600R cstecgi.cgi setParentalRules buffer overflow
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182B20201102. It has been rated as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument startTime/endTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272600. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7179?
CVE-2024-7179 has been rated as critical due to a buffer overflow vulnerability.
How do I fix CVE-2024-7179?
To fix CVE-2024-7179, update the TOTOLINK A3600R firmware to the latest version to mitigate the vulnerability.
What component is affected by CVE-2024-7179?
CVE-2024-7179 affects the setParentalRules function within the /cgi-bin/cstecgi.cgi file.
What is the attack vector for CVE-2024-7179?
The attack vector for CVE-2024-7179 involves manipulating the arguments startTime and endTime, leading to potential exploitation.
Which devices are impacted by CVE-2024-7179?
CVE-2024-7179 impacts devices running TOTOLINK A3600R firmware version 4.1.2cu.5182_B20201102.