Vulnerability Details CVE-2024-7177
                A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. Affected is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument langType leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272598 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.002
                        
                    
                    
                        
                            EPSS Ranking 45.9%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 8.8
                        
                    
                    
                        
                            CVSS v2 Score 9.0
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2024-7177
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:h:totolink:a3600r:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:totolink:a3600r_firmware:4.1.2cu.5182_b20201102