TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter.
References
Link | Resource |
---|---|
https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/TOTOLINK/AC1200T8/UploadCustomModule.md | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
17 Sep 2024, 14:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
17 Sep 2024, 11:48
Type | Values Removed | Values Added |
---|---|---|
First Time |
Totolink
Totolink t8 Firmware Totolink t8 |
|
References | () https://github.com/TTTJJJWWW/AHU-IoT-vulnerable/blob/main/TOTOLINK/AC1200T8/UploadCustomModule.md - Exploit, Third Party Advisory | |
CPE | cpe:2.3:o:totolink:t8_firmware:4.1.5cu.861_b20230220:*:*:*:*:*:*:* cpe:2.3:h:totolink:t8:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-120 |
16 Sep 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-16 13:15
Updated : 2024-09-17 14:35
NVD link : CVE-2024-46424
Mitre link : CVE-2024-46424
CVE.ORG link : CVE-2024-46424
JSON object : View
Products Affected
totolink
- t8_firmware
- t8
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')