Vulnerability Description
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Totolink | Nr1800X Firmware | 9.1.0u.6279_b20210910 |
| Totolink | Nr1800X | - |
Related Weaknesses (CWE)
References
- https://github.com/Archerber/bug_submit/blob/main/TOTOLINK/TOTOLINK-NR1800X.mdExploitThird Party Advisory
- https://github.com/Archerber/bug_submit/blob/main/TOTOLINK/TOTOLINK-NR1800X.mdExploitThird Party Advisory
FAQ
What is CVE-2023-36340?
CVE-2023-36340 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
How severe is CVE-2023-36340?
CVE-2023-36340 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-36340?
Check the references section above for vendor advisories and patch information. Affected products include: Totolink Nr1800X Firmware, Totolink Nr1800X.