TOTOLINK A3300R
cpe:2.3:h:totolink:a3300r:*:*:*:*:*:*:*, +1 more
- 17.0.0cu.557_B20221024
A buffer overflow vulnerability has been identified in the TOTOLINK A3300R router, specifically in the firmware version 17.0.0cu.557_B20221024. The issue arises in the 'setDdnsCfg' function within the file '/cgi-bin/cstecgi.cgi'. This vulnerability can be exploited remotely, and a public exploit is available.
Exploitation of this vulnerability leads to a stack-based buffer overflow, which can commonly result in arbitrary code execution or causing the device to crash.
The vulnerability can be reproduced by sending a POST request to the '/cgi-bin/cstecgi.cgi' endpoint with a crafted 'provider' parameter. This parameter is not properly validated for length, allowing for an overflow when the 'provider' value is read back via the 'getDdnsCfg' function.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.