Stack Overflow Vulnerability in TOTOLINK X2000R by TOTOLINK
CVE-2023-46556

9.8CRITICAL

Key Information:

Vendor
Totolink
Vendor
CVE Published:
25 October 2023

Summary

The TOTOLINK X2000R suffers from a stack overflow vulnerability in the formFilter function, allowing attackers to execute arbitrary code or cause a denial of service. This flaw is present in version Gh v1.0.0-B20230221.0948.web, highlighting the need for immediate remediation to ensure network device security. Affected users should consider applying patches or updates provided by TOTOLINK to mitigate potential exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.