HIGH🇵🇱 Wersja polska

CVE-2024-7336

CVSS 8.7v4.0pub. 2024-08-01upd. 2024-08-09

A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273259. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Totolink Ex200

    HW
    Totolink
    all versions
  • Totolink Ex200 Firmware

    OS
    Totolink
    4.0.3c.7646_b20201211
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-31810CRITICAL9.8PL ✓same product

TOTOLINK EX200: zakodowane na stałe hasło roota w firmware

CVE-2024-31815CRITICAL9.1PL ✓same product

TOTOLINK EX200 – nieautoryzowany dostęp do pliku konfiguracyjnego

CVE-2024-31807CRITICAL9.8PL ✓same product

RCE w TOTOLINK EX200 poprzez parametr hostTime w funkcji NTPSyncWithHost

CVE-2021-43711CRITICAL9.8PL ✓same product

Command injection w TOTOLINK EX200 — nieuwierzytelnione RCE przez downloadFlile.cgi

CVE-2024-7335HIGH8.7same product

A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the...