CVE-2024-8575: TOTOLINK AC1200 T8 cstecgi.cgi setWiFiScheduleCfg buffer overflow
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8575?
CVE-2024-8575 is classified as critical due to its potential for remote exploitation and buffer overflow vulnerabilities.
How do I fix CVE-2024-8575?
To fix CVE-2024-8575, users should update their TOTOLINK AC1200 T8 firmware to a version that addresses this vulnerability.
What software versions are affected by CVE-2024-8575?
CVE-2024-8575 affects the TOTOLINK T8 firmware version 4.1.5cu.861_B20230220.
Can CVE-2024-8575 be exploited remotely?
Yes, CVE-2024-8575 can be exploited remotely through manipulation of specific arguments.
What function is vulnerable in CVE-2024-8575?
The function setWiFiScheduleCfg in the file /cgi-bin/cstecgi.cgi is vulnerable in CVE-2024-8575.