Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-34198


TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying an excessively long value for the wlan_ssid field, leading to a stack overflow. This can be further exploited to execute arbitrary commands or launch denial-of-service attacks.


Published

2024-08-28T15:15:16.503

Last Modified

2025-07-03T11:58:29.933

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System totolink a3002ru_firmware 2.1.1-b20230720.1011 Yes
Hardware totolink a3002ru - No

References