ID

VAR-202409-0681


CVE

CVE-2024-46424


TITLE

TOTOLINK  of  T8  Classic buffer overflow vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2024-008273

DESCRIPTION

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the File parameter. TOTOLINK AC1200 is a dual-band Wi-Fi router from China's TOTOLINK Electronics. There is a buffer overflow vulnerability in the UploadCustomModule function of TOTOLINK AC1200. The vulnerability is caused by the File parameter of the UploadCustomModule function failing to correctly verify the length of the input data

Trust: 2.16

sources: NVD: CVE-2024-46424 // JVNDB: JVNDB-2024-008273 // CNVD: CNVD-2025-00877

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-00877

AFFECTED PRODUCTS

vendor:totolinkmodel:t8scope:eqversion:4.1.5cu.861_b20230220

Trust: 1.0

vendor:totolinkmodel:t8scope:eqversion: -

Trust: 0.8

vendor:totolinkmodel:t8scope: - version: -

Trust: 0.8

vendor:totolinkmodel:t8scope:eqversion:t8 firmware 4.1.5cu.861 b20230220

Trust: 0.8

vendor:totolinkmodel:ac1200 v4.1.5cu.861 b20230220scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-00877 // JVNDB: JVNDB-2024-008273 // NVD: CVE-2024-46424

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2024-46424
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-46424
value: HIGH

Trust: 1.0

NVD: CVE-2024-46424
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-00877
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-00877
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2024-46424
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 2.0

NVD: CVE-2024-46424
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-00877 // JVNDB: JVNDB-2024-008273 // NVD: CVE-2024-46424 // NVD: CVE-2024-46424

PROBLEMTYPE DATA

problemtype:CWE-120

Trust: 1.0

problemtype:Classic buffer overflow (CWE-120) [NVD evaluation ]

Trust: 0.8

problemtype: Classic buffer overflow (CWE-120) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-008273 // NVD: CVE-2024-46424

EXTERNAL IDS

db:NVDid:CVE-2024-46424

Trust: 3.2

db:JVNDBid:JVNDB-2024-008273

Trust: 0.8

db:CNVDid:CNVD-2025-00877

Trust: 0.6

sources: CNVD: CNVD-2025-00877 // JVNDB: JVNDB-2024-008273 // NVD: CVE-2024-46424

REFERENCES

url:https://github.com/tttjjjwww/ahu-iot-vulnerable/blob/main/totolink/ac1200t8/uploadcustommodule.md

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-46424

Trust: 1.4

sources: CNVD: CNVD-2025-00877 // JVNDB: JVNDB-2024-008273 // NVD: CVE-2024-46424

SOURCES

db:CNVDid:CNVD-2025-00877
db:JVNDBid:JVNDB-2024-008273
db:NVDid:CVE-2024-46424

LAST UPDATE DATE

2025-01-11T23:16:19.093000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-00877date:2025-01-10T00:00:00
db:JVNDBid:JVNDB-2024-008273date:2024-09-18T02:48:00
db:NVDid:CVE-2024-46424date:2024-09-17T14:35:30.557

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-00877date:2025-01-10T00:00:00
db:JVNDBid:JVNDB-2024-008273date:2024-09-18T00:00:00
db:NVDid:CVE-2024-46424date:2024-09-16T13:15:10.760