PT-2022-23385 · Totolink · Totolink A3700R

CVE-2022-36462

·

Published

2022-08-25

·

Updated

2025-06-08

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK A3700R version 9.1.2u.6134 B20201202
Description A stack overflow issue was discovered in the setLanguageCfg function via the lang parameter.
Recommendations For version 9.1.2u.6134 B20201202, avoid using the lang parameter in the setLanguageCfg function until a fix is available. As a temporary workaround, consider restricting access to the setLanguageCfg function to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36462

Affected Products

Totolink A3700R