漏洞标题
TOTOLINK X18 cstecgi.cgi setPasswordCfg 堆栈溢出漏洞
漏洞描述信息
在TOTOLINK X18 9.1.0cu.2024_B20220329版本中发现了一个被归类为关键级别的漏洞。该漏洞影响文件 `/cgi-bin/cstecgi.cgi` 中的 `setPasswordCfg` 函数。由于字符串操作导致了基于堆栈的缓冲区溢出。此攻击可以通过远程方式进行。该漏洞的利用方法已被公开披露,并可能被利用。尽管已提前通知了厂商,但厂商未对此作出任何回应。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
跨界内存写
漏洞标题
TOTOLINK X18 cstecgi.cgi setPasswordCfg stack-based overflow
漏洞描述信息
A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation as part of String leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
栈缓冲区溢出