CVE-2022-36480: High severity totolink n350rt firmware vulnerability
Published Aug 25, 2022
·Updated
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.
Affected Software
2 affected components
Totolink N350RT Firmware=9.3.5u.6139_b20201216
Totolink N350RT Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36480?
CVE-2022-36480 is considered a high-severity vulnerability due to the potential for remote code execution through stack overflow.
2
How do I fix CVE-2022-36480?
To mitigate CVE-2022-36480, update the TOTOLINK N350RT firmware to a version that addresses this vulnerability.
3
What are the potential impacts of CVE-2022-36480?
The potential impacts of CVE-2022-36480 include unauthorized access and control of the affected N350RT device.
4
Which versions of TOTOLINK N350RT are vulnerable to CVE-2022-36480?
TOTOLINK N350RT firmware version 9.3.5u.6139_B20201216 is known to be vulnerable to CVE-2022-36480.
5
How can CVE-2022-36480 be exploited?
CVE-2022-36480 can be exploited by sending specially crafted commands to the device, leading to a stack overflow condition.