CVE-2024-0575

HIGH

Totolink LR1200GB 9.1.0u.6619_B20230130 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250791. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.250791
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.250791

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 60.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
totolink/lr1200gb_firmware 9.1.0u.6619_b20230130
Published Jan 16, 2024
Tracked Since Feb 18, 2026