ID

VAR-202411-1990


CVE

CVE-2024-53335


TITLE

TOTOLINK  of  a810r  Classic buffer overflow vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2024-021784

DESCRIPTION

TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi. TOTOLINK of a810r Firmware has a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TOTOLINK A810R is a wireless dual-band router from China's TOTOLINK Electronics. TOTOLINK A810R has a buffer overflow vulnerability, which is caused by the failure of downloadFlile.cgi to properly verify the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service

Trust: 2.16

sources: NVD: CVE-2024-53335 // JVNDB: JVNDB-2024-021784 // CNVD: CNVD-2025-12401

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-12401

AFFECTED PRODUCTS

vendor:totolinkmodel:a810rscope:eqversion:4.1.2cu.5182_b20201026

Trust: 1.0

vendor:totolinkmodel:a810rscope:eqversion: -

Trust: 0.8

vendor:totolinkmodel:a810rscope: - version: -

Trust: 0.8

vendor:totolinkmodel:a810rscope:eqversion:a810r firmware 4.1.2cu.5182 b20201026

Trust: 0.8

vendor:totolinkmodel:a810r v4.1.2cu.5182 b20201026scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-12401 // JVNDB: JVNDB-2024-021784 // NVD: CVE-2024-53335

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-53335
value: HIGH

Trust: 1.0

OTHER: JVNDB-2024-021784
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-12401
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-12401
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-53335
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2024-021784
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-12401 // JVNDB: JVNDB-2024-021784 // NVD: CVE-2024-53335

PROBLEMTYPE DATA

problemtype:CWE-120

Trust: 1.0

problemtype:Classic buffer overflow (CWE-120) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-021784 // NVD: CVE-2024-53335

EXTERNAL IDS

db:NVDid:CVE-2024-53335

Trust: 3.2

db:JVNDBid:JVNDB-2024-021784

Trust: 0.8

db:CNVDid:CNVD-2025-12401

Trust: 0.6

sources: CNVD: CNVD-2025-12401 // JVNDB: JVNDB-2024-021784 // NVD: CVE-2024-53335

REFERENCES

url:https://github.com/luckysmallbird/totolink-a810r-vulnerability-1/blob/main/2.md

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-53335

Trust: 1.4

sources: CNVD: CNVD-2025-12401 // JVNDB: JVNDB-2024-021784 // NVD: CVE-2024-53335

SOURCES

db:CNVDid:CNVD-2025-12401
db:JVNDBid:JVNDB-2024-021784
db:NVDid:CVE-2024-53335

LAST UPDATE DATE

2025-06-15T23:42:19.735000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-12401date:2025-06-13T00:00:00
db:JVNDBid:JVNDB-2024-021784date:2025-04-10T02:59:00
db:NVDid:CVE-2024-53335date:2025-04-04T14:39:54.600

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-12401date:2025-06-13T00:00:00
db:JVNDBid:JVNDB-2024-021784date:2025-04-10T00:00:00
db:NVDid:CVE-2024-53335date:2024-11-21T18:15:14.153