Skip to content

Instantly share code, notes, and snippets.

@Swind1er
Swind1er / CVE-2024-31616.md
Last active April 20, 2024 00:22
CVE-2024-31616

[CVE ID]

CVE-2024-31616 [PRODUCT] RG-RSR10-01G-T(W)-S RG-RSR10-01G-T(WA)-S

[VERSION]

RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910)

[CVE ID]

CVE-2024-32394 [PRODUCT] RG-RSR10-01G-T(W)-S RG-RSR10-01G-T(WA)-S

[VERSION]

RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910)

setUploadSettingRCE

Poc

Firmware Version: A3100R_V4.1.2cu.5247_B20211129

You can download the firmware here: Swind1er/Download (github.com)

Vulnerability Proof of Concept Video:

setWebWlanIdx RCE

Poc

"Firmware version:"A3100R_V4.1.2cu.5247_B20211129

You can download the firmware here: Swind1er/Download (github.com)

Vulnerability demonstration video:

CVE-2024-36650

Vulnerability Type: Stack Overflow

CVE-ID:CVE-2024-36650

Vendor of Product: https://www.totolink.net/

Poc

Firmware version: A3100R_V4.1.2cu.5247_B20211129

setPortForwardRules StackOverflow

Poc

Firmware version: A3100R_V4.1.2cu.5247_B20211129

You can download the firmware here: Swind1er/Download (github.com)

Vulnerability demonstration video: