CVE-2024-0576
Totolink
CVE-2024-0576 is a critical stack-based buffer overflow vulnerability found in Totolink LR1200GB routers. Specifically, version 9.1.0u.6619_B20230130 is affected when handling the 'sPort' argument in the setIpPortFilterRules function within the /cgi-bin/cstecgi.cgi file. A remote attacker can exploit this flaw by manipulating the 'sPort' parameter. Despite the high CVSS score of 9.8, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting that while the vulnerability is inherently severe, real-world exploitability and risk may be lower due to factors such as limited active exploitation or compensating controls. Nevertheless, this vulnerability poses a significant risk of remote code execution, potentially allowing attackers to gain complete control of the affected Totolink router. It is crucial to monitor for exploit attempts and consider mitigation strategies despite the vendor's lack of response. This can lead to severe network security compromises if exploited.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.