TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Totolink A3600r_Firmware
cpe:2.3:o:totolink:a3600r_firmware:5.9c.4959:*:*:*:*:*:*:*
|
— | — |
|
Totolink A3600r
cpe:2.3:h:totolink:a3600r:-:*:*:*:*:*:*:*
|
— | — |