← Vulnerability feed

Vulnerability record · CVE-2024-34209 · published 14 May 2024

CVE-2024-34209: Totolink cp450 firmware stack-based buffer overflow vulnerability

TTotolink · Cp450 Firmware

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.

9.8 CVSS 3.1 Critical EPSS 0.94% · top 40.8% CWE-121 · Stack-based buffer overflow
9.8CVSS 3.1 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-34209 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-34213Totolink cp450 firmware stack-based buffer overflow vulnerabilityTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.EPSS 0.94%9.8CVE-2024-34204Totolink cp450 firmware command injection vulnerabilityTOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the Fi…EPSS 1.9%9.3CVE-2024-7332Totolink cp450 firmware hard-coded password vulnerabilityA vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_…EPSS 21%8.8CVE-2024-34207Totolink cp450 firmware stack-based buffer overflow vulnerabilityTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.EPSS 0.79%8.8CVE-2024-34211Totolink cp450 firmware hard-coded password vulnerabilityTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to l…EPSS 0.55%8.8CVE-2024-34200Totolink cp450 firmware out-of-bounds read vulnerabilityTOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.EPSS 0.91%8.7CVE-2024-7465Totolink cp450 firmware classic buffer overflow vulnerabilityA vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file …EPSS 1.3%8.6CVE-2024-34219Totolink cp450 firmware hard-coded credentials vulnerabilityTOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in throug…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2024-34209), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.