CVE-2024-7333
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Aug 1, 2024
Updated: Aug 9, 2024
CWE ID 120
Summary
CVE-2024-7333 is a critical vulnerability affecting the TOTOLINK N350RT with version 9.3.5u.6139_B20201216. This issue resides in the function setParentalRules of the file /cgi-bin/cstecgi.cgi, where manipulation of the arguments week/sTime/eTime results in a buffer overflow. A remote attacker can exploit this vulnerability, and the exploit has already been made public. The identifier for this issue is VDB-273356, and unfortunately, the vendor did not respond to early disclosure attempts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- TOTOLINK