CVE-2022-36488: High severity totolink n350rt firmware vulnerability
Published Aug 25, 2022
·Updated
TOTOLINK N350RT V9.3.5u.6139B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.
Affected Software
2 affected components
Totolink N350RT Firmware=9.3.5u.6139_b20201216
Totolink N350RT Firmware
Event History
Aug 25, 2022
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36488?
CVE-2022-36488 has a high severity due to the potential for remote exploitation through a stack overflow.
2
How do I fix CVE-2022-36488?
To fix CVE-2022-36488, upgrade the TOTOLINK N350RT firmware to a version that addresses this vulnerability.
3
What attack vectors are associated with CVE-2022-36488?
CVE-2022-36488 can be exploited via the sPort parameter in the setIpPortFilterRules function, leading to a stack overflow.
4
Which devices are affected by CVE-2022-36488?
The TOTOLINK N350RT device running firmware version 9.3.5u.6139_B20201216 is specifically affected by CVE-2022-36488.
5
What are the potential consequences of exploiting CVE-2022-36488?
Exploiting CVE-2022-36488 may allow attackers to execute arbitrary code on the vulnerable device.