CVE-2024-7465: TOTOLINK CP450 cstecgi.cgi loginauth buffer overflow
A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument httphost leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273558 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7465?
CVE-2024-7465 is classified as a critical vulnerability.
How do I fix CVE-2024-7465?
To fix CVE-2024-7465, update the TOTOLINK CP450 firmware to the latest available version.
What is the impact of CVE-2024-7465?
The impact of CVE-2024-7465 includes the potential for remote attackers to exploit a buffer overflow, leading to unauthorized access.
Which software versions are affected by CVE-2024-7465?
CVE-2024-7465 affects the TOTOLINK CP450 firmware version 4.1.0cu.747_B20191224.
Can CVE-2024-7465 be exploited remotely?
Yes, CVE-2024-7465 can be exploited remotely due to its nature of a buffer overflow in the loginauth function.