Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-36650

Опубликовано: 11 июн. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function setNoticeCfg of the file /lib/cste_modules/system.so, the length of the user input string NoticeUrl is not checked. This can lead to a buffer overflow, allowing attackers to construct malicious HTTP or MQTT requests to cause a denial-of-service attack.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00304
Низкий

7.5 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_modules/system.so`, the length of the user input string `NoticeUrl` is not checked. This can lead to a buffer overflow, allowing attackers to construct malicious HTTP or MQTT requests to cause a denial-of-service attack.

EPSS

Процентиль: 53%
0.00304
Низкий

7.5 High

CVSS3

Дефекты

CWE-120