github.comexploit
https://github.com/abcdefg-png/IoT-vulnerable/blob/main/TOTOLINK/A3600R/setLanguageCfg.md CVE-2024-7177
HIGH
TOTOLINK A3600R cstecgi.cgi setLanguageCfg buffer overflow
Record summary
CVE-2024-7177 has a selected CVSS score of 8.7 (high).
Description
A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. Affected is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument langType leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272598 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 29, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
A3600RBrowse TOTOLINK / A3600R | CVE List | 4.1.2cu.5182_B20201102 | affected |
a3600r_firmwareBrowse totolink / a3600r_firmwareDefault status: unknown | CVE List | 4.1.2cu.5182_b20201102 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-7177 VDB-272598 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/?ctiid.272598 VDB-272598 | TOTOLINK A3600R cstecgi.cgi setLanguageCfg buffer overflowvdb entryTechnical description
https://vuldb.com/?id.272598 Submit #378044 | TOTOLINK A3600R V4.1.2cu.5182_B20201102 Buffer OverflowThird-party advisory
https://vuldb.com/?submit.378044