CVE-2024-7154

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jul 28, 2024
Updated: Aug 8, 2024
CWE ID 306
CWE ID 284

Summary

CVE-2024-7154 is a newly disclosed vulnerability affecting the TOTOLINK A3700R's Password Reset Handler component. The issue lies within an unknown function of the /wizard.html file and results in improper access controls. An attacker can exploit this remotely, leading to potential security breaches. The vulnerability, identified as VDB-272568, has been made public, increasing the risk of exploitation. The vendor was notified but did not respond to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share