CVE-2024-34196
HIGHTotolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware - Buffer Overflow
Title source: llmDescription
Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of the "vwlan_idx" field via "formMultiAP". This can lead to a stack overflow through the "formWlEncrypt" CGI function by constructing malicious HTTP requests and passing a WLAN SSID value exceeding the expected length, potentially resulting in command execution or denial of service attacks.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://gist.github.com/Swind1er/1ec2fde42254598a72f1d716f9cfe2a1
Scores
CVSS v3
8.8
EPSS
0.0009
EPSS Percentile
26.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-120
Status
published
Products (1)
totolink/a3002ru-v3_firmware
3.0.0-b20230809.1615
Published
May 14, 2024
Tracked Since
Feb 18, 2026