← Vulnerability feed

Vulnerability record · CVE-2024-7217 · published 30 July 2024

CVE-2024-7217: Totolink ca300-poe firmware classic buffer overflow vulnerability

TTotolink · Ca300 Poe Firmware

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. This vulnerability affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272788. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

5.3 CVSS 4.0 Medium EPSS 6.8% · top 6.3% CWE-120 · Classic buffer overflow
5.3CVSS 4.0 base score, v2 6.5
6.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. This vulnerability affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272788. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7217 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-24159Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.EPSS 1.9%9.8CVE-2023-24160Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.EPSS 1.9%9.8CVE-2023-24161Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.EPSS 1.9%9.8CVE-2023-24148Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.EPSS 1.8%9.8CVE-2023-24149Totolink ca300-poe firmware hard-coded credentials vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.EPSS 0.82%9.8CVE-2023-24142Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag func…EPSS 1.9%9.8CVE-2023-24143Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag fu…EPSS 1.9%9.8CVE-2023-24144Totolink ca300-poe firmware command injection vulnerabilityTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2024-7217), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.