Vulnerability Description
Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit the length of the wlan_ssid field triggers the overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | A3002R Firmware | 4.0.0-b20230531.1404 |
| Totolink | A3002R | v4 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Swind1er/ee095fbfe13f77a5b45b39a5aa82bd17ExploitThird Party Advisory
- https://gist.github.com/Swind1er/ee095fbfe13f77a5b45b39a5aa82bd17ExploitThird Party Advisory
FAQ
What is CVE-2024-33820?
CVE-2024-33820 is a vulnerability with a CVSS score of 7.5 (HIGH). Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they exploit...
How severe is CVE-2024-33820?
CVE-2024-33820 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-33820?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink A3002R Firmware, Totolink A3002R.