Stack Overflow Vulnerability in H3C Magic R300 Router
CVE-2023-33640

7.2HIGH

Key Information:

Vendor
H3c
Vendor
CVE Published:
31 May 2023

Summary

The H3C Magic R300 router, specifically version R300-2100MV100R004, has been identified with a stack overflow vulnerability. This issue can be exploited through the SetAPWifiorLedInfoById interface found in the /goform/aspForm endpoint, potentially allowing attackers to execute arbitrary code and disrupt network services. Network administrators are urged to apply necessary patches and enhance security measures to safeguard their infrastructure from unauthorized access and potential exploits.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.