Description
TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_modules/system.so`, the length of the user input string `NoticeUrl` is not checked. This can lead to a buffer overflow, allowing attackers to construct malicious HTTP or MQTT requests to cause a denial-of-service attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 04 Jun 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink a3100r Firmware
|
|
| CPEs | cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:* | |
| Vendors & Products |
Totolink a3100r Firmware
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T03:37:05.419Z
Reserved: 2024-05-30T00:00:00.000Z
Link: CVE-2024-36650
Updated: 2024-06-11T20:31:56.501Z
Status : Analyzed
Published: 2024-06-11T16:15:29.043
Modified: 2025-06-04T17:24:49.253
Link: CVE-2024-36650
No data.
OpenCVE Enrichment
No data.
Weaknesses