8.8
CVSSv3

CVE-2024-8576

CVSSv4: 8.7 | CVSSv3: 8.8 | CVSSv2: 9 | VMScore: 970 | EPSS: 0.00319 | KEV: Not Included
Published: 08/09/2024 Updated: 09/09/2024

Vulnerability Summary

Critical Buffer Overflow in TOTOLINK AC1200 Routers

A critical vulnerability is present in TOTOLINK AC1200 T8 and AC1200 T10 versions 4.1.5cu.861_B20230220/4.1.8cu.5207. It affects the function setIpPortFilterRules in the file /cgi-bin/cstecgi.cgi. Manipulating the desc argument here causes a buffer overflow. This can be exploited remotely. The exploit has been publicly disclosed. The vendor was informed early about this issue, but they did not respond.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

totolink t8 firmware 4.1.5cu.861 b20230220

totolink t10 firmware 4.1.8cu.5207

Vendor Advisories