Vulnerability Description
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr940N Firmware | - |
| Tp-Link | Tl-Wr940N | v4 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/173294/TP-Link-TL-WR940N-4-Buffer-Overflow.
- https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/9/TP-Link%20TL-WR940N%2ExploitThird Party Advisory
- http://packetstormsecurity.com/files/173294/TP-Link-TL-WR940N-4-Buffer-Overflow.
- https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/9/TP-Link%20TL-WR940N%2ExploitThird Party Advisory
FAQ
What is CVE-2023-36355?
CVE-2023-36355 is a vulnerability with a CVSS score of 9.9 (CRITICAL). TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via ...
How severe is CVE-2023-36355?
CVE-2023-36355 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-36355?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr940N Firmware, Tp-Link Tl-Wr940N.