Vulnerability Description
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | Nr1800X Firmware | 9.1.0u.6279_b20210910 |
| Totolink | Nr1800X | - |
Related Weaknesses (CWE)
References
- https://brief-nymphea-813.notion.site/NR1800X-bof-setOpModeCfg-2e286823203c405bbExploitThird Party Advisory
- https://brief-nymphea-813.notion.site/NR1800X-bof-setOpModeCfg-2e286823203c405bbExploitThird Party Advisory
FAQ
What is CVE-2022-41527?
CVE-2022-41527 is a vulnerability with a CVSS score of 8.8 (HIGH). TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg function.
How severe is CVE-2022-41527?
CVE-2022-41527 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41527?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink Nr1800X Firmware, Totolink Nr1800X.