CVE-2024-22662
https://notcve.org/view.php?id=CVE-2024-22662
TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules TOTOLINK A3700R_V9.1.2u.6165_20211012 tiene una vulnerabilidad de desbordamiento en la región stack de la memoria a través de setParentalRules • https://github.com/Covteam/iot_vuln/tree/main/setParentalRules • CWE-787: Out-of-bounds Write •
CVE-2024-22663
https://notcve.org/view.php?id=CVE-2024-22663
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg TOTOLINK_A3700R_V9.1.2u.6165_20211012 tiene una vulnerabilidad de inyección de comando a través de setOpModeCfg • https://github.com/Covteam/iot_vuln/tree/main/setOpModeCfg2 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2024-0579 – Totolink X2000R formMapDelDevice command injection
https://notcve.org/view.php?id=CVE-2024-0579
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/jylsec/vuldb/blob/main/TOTOLINK/X2000R/1/README.md https://vuldb.com/?ctiid.250795 https://vuldb.com/?id.250795 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2024-0578 – Totolink LR1200GB cstecgi.cgi UploadCustomModule stack-based overflow
https://notcve.org/view.php?id=CVE-2024-0578
A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/jylsec/vuldb/blob/main/TOTOLINK/LR1200GB/8/README.md https://vuldb.com/?ctiid.250794 https://vuldb.com/?id.250794 • CWE-121: Stack-based Buffer Overflow •
CVE-2024-0577 – Totolink LR1200GB cstecgi.cgi setLanguageCfg stack-based overflow
https://notcve.org/view.php?id=CVE-2024-0577
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be initiated remotely. • https://github.com/jylsec/vuldb/blob/main/TOTOLINK/LR1200GB/7/README.md https://vuldb.com/?ctiid.250793 https://vuldb.com/?id.250793 • CWE-121: Stack-based Buffer Overflow •