CVE-2024-8577
Totolink
CVE-2024-8577: Critical buffer overflow vulnerability in TOTOLINK AC1200 T8 and T10 routers. This vulnerability, found in the setStaticDhcpRules function of /cgi-bin/cstecgi.cgi, allows remote attackers to execute arbitrary code by manipulating the 'desc' argument. The CVSS score is 8.8, and while the SOCRadar Vulnerability Risk Score (SVRS) is 77, indicating high risk, it's close to the critical threshold. With a public exploit available and no vendor response, immediate patching or mitigation is strongly advised to prevent potential remote code execution. This buffer overflow could lead to complete system compromise.
Description
CVE-2024-8577 is a critical vulnerability in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It allows remote attackers to execute arbitrary code on affected devices by manipulating the desc argument in the setStaticDhcpRules function of the /cgi-bin/cstecgi.cgi file. The vulnerability has been publicly disclosed and may be actively exploited.
Key Insights
- The CVSS score of 8.8 indicates a high severity vulnerability.
- The SVRS of 82 signifies a critical vulnerability that requires immediate attention.
- The vulnerability can be exploited remotely, making it easy for attackers to target affected devices.
- The vendor has not responded to the disclosure, leaving users vulnerable to exploitation.
Mitigation Strategies
- Update to the latest firmware version as soon as possible.
- Disable remote access to the affected devices.
- Implement network segmentation to limit the spread of an attack.
- Monitor network traffic for suspicious activity.
Additional Information
- Threat Actors/APT Groups: Not specified
- Exploit Status: Active exploits have been published
- CISA Warnings: The Cybersecurity and Infrastructure Security Agency (CISA) has warned of the vulnerability, calling for immediate and necessary measures.
- In the Wild: The vulnerability is actively exploited by hackers
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.