Stack-Based Buffer Overflow in TOTOLINK T10_v2
CVE-2023-40042
9.8CRITICAL
Summary
The TOTOLINK T10_v2 5.9c.5061_B20200511 suffers from a stack-based buffer overflow in the 'setStaticDhcpConfig' function located in '/lib/cste_modules/lan.so'. This vulnerability allows attackers to send specially crafted data via the comment parameter in an MQTT packet. By controlling the return address during this process, malicious actors can execute arbitrary code, potentially compromising the device and the network it operates within. Timely patching and updates are crucial to mitigate the risk associated with this vulnerability.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved