CVE-2024-7337: TOTOLINK EX1200L cstecgi.cgi loginauth buffer overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146B20201023. Affected by this issue is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument httphost leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273260. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7337?
CVE-2024-7337 is classified as critical due to its potential to lead to a buffer overflow vulnerability.
How do I fix CVE-2024-7337?
To mitigate CVE-2024-7337, users should update to the latest firmware version provided by TOTOLINK.
Which devices are affected by CVE-2024-7337?
CVE-2024-7337 affects the TOTOLINK EX1200L running firmware version 9.3.5u.6146_B20201023.
What type of vulnerability is CVE-2024-7337?
CVE-2024-7337 is a buffer overflow vulnerability that can be exploited through the function loginauth in the affected firmware.
What impact can CVE-2024-7337 have on my device?
Exploitation of CVE-2024-7337 could allow attackers to execute arbitrary code, potentially compromising the device's security.