TOTOLINK N150RT
cpe:2.3:h:totolink:n150rt:*:*:*:*:*:*:*, +3 more
- 3.4.0-B20190525
A critical buffer overflow vulnerability has been identified in the TOTOLINK N150RT router, specifically in the V2_Firmware V3.4.0-B20190525. The issue arises in the file '/boafrm/formWlwds', where the 'submit-url' parameter can be manipulated, leading to a buffer overflow. This vulnerability can be exploited remotely.
Exploitation of this vulnerability causes a denial-of-service condition, where the device becomes unresponsive and cannot be accessed via the network.
The vulnerability can be reproduced by sending a POST request to the '/boafrm/formWlwds' endpoint with a crafted 'submit-url' parameter that exceeds the buffer size, causing a buffer overflow. This can be done using a tool like Burp Suite. After sending the request, the device's web server will become unresponsive, indicating that the buffer overflow has been successfully exploited.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.