8.8
CVSSv3

CVE-2024-8577

CVSSv4: 8.7 | CVSSv3: 8.8 | CVSSv2: 9 | VMScore: 970 | EPSS: 0.00319 | KEV: Not Included
Published: 08/09/2024 Updated: 09/09/2024

Vulnerability Summary

Remote Buffer Overflow in TOTOLINK AC1200 Routers

A critical vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 versions 4.1.5cu.861_B20230220 and 4.1.8cu.5207. This affects the setStaticDhcpRules function in the file /cgi-bin/cstecgi.cgi. Manipulating the desc argument can cause a buffer overflow. This attack can be done remotely. The exploit has been shared publicly and can be used. The vendor was informed early but did not reply.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

totolink t8 firmware 4.1.5cu.861 b20230220

totolink t10 firmware 4.1.8cu.5207

Vendor Advisories