Lucene search

K
nvd[email protected]NVD:CVE-2024-34196
HistoryMay 14, 2024 - 3:38 p.m.

CVE-2024-34196

2024-05-1415:38:32
web.nvd.nist.gov
totolink ac1200
buffer overflow
stack overflow
formmultiap
formwlencrypt
command execution
denial of service

7.1 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The “boa” program allows attackers to modify the value of the “vwlan_idx” field via “formMultiAP”. This can lead to a stack overflow through the “formWlEncrypt” CGI function by constructing malicious HTTP requests and passing a WLAN SSID value exceeding the expected length, potentially resulting in command execution or denial of service attacks.

7.1 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Related for NVD:CVE-2024-34196