TOTOLINK LR1200GB是中国吉翁电子(TOTOLINK)公司的一款无线双频 4G LTE 路由器。 TOTOLINK LR1200GB 9.1.0u.6619_B20230130 版本存在安全漏洞,该漏洞源于 /cgi-bin/cstecgi.cgi 文件的 setParentalRules 函数的 sTime 参数存在缓冲区溢出漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-0571 | 8.8 HIGH | Totolink LR1200GB cstecgi.cgi setSmsCfg stack-based overflow |
| CVE-2024-0572 | 8.8 HIGH | Totolink LR1200GB cstecgi.cgi setOpModeCfg stack-based overflow |
| CVE-2024-0573 | 8.8 HIGH | Totolink LR1200GB cstecgi.cgi setDiagnosisCfg stack-based overflow |
| CVE-2024-0575 | 8.8 HIGH | Totolink LR1200GB cstecgi.cgi setTracerouteCfg stack-based overflow |
| CVE-2024-0576 | 8.8 HIGH | Totolink LR1200GB cstecgi.cgi setIpPortFilterRules stack-based overflow |
| CVE-2024-0577 | 8.8 HIGH | Totolink LR1200GB cstecgi.cgi setLanguageCfg stack-based overflow |
| CVE-2024-0578 | 8.8 HIGH | Totolink LR1200GB cstecgi.cgi UploadCustomModule stack-based overflow |
| CVE-2024-0570 | 7.3 HIGH | Totolink N350RT Setting cstecgi.cgi access control |
| CVE-2024-0579 | 6.3 MEDIUM | Totolink X2000R formMapDelDevice command injection |
| CVE-2024-0569 | 4.3 MEDIUM | Totolink T8 Setting cstecgi.cgi getSysStatusCfg information disclosure |
No comments yet