CVE-2024-34198: Totolink a3002ru Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying an excessively long value for the wlan_ssid field, leading to a stack overflow. This can be further exploited to execute arbitrary commands or launch denial-of-service attacks.

Affected products

  • Totolink a3002ru Firmware: version 2.1.1-b20230720.1011 only

Published 2024-08-28. Last modified 2026-06-17.