CVE-2023-33485: Buffer Overflow
Published May 31, 2023
·Updated
TOTOLINK X5000R V9.1.0u.6118B20201102 and V9.1.0u.6369B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.
Affected Software
7 affected components
All of the following
TOTOLINK X5000r Firmware=9.1.0u.6118_b20201102
TOTOLINK X5000R
All of the following
TOTOLINK X5000r Firmware=9.1.0u.6369_b20230113
TOTOLINK X5000R
TOTOLINK X5000r Firmware=9.1.0u.6118_b20201102
TOTOLINK X5000R
TOTOLINK X5000r Firmware=9.1.0u.6369_b20230113
Event History
May 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
01:15 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for TOTOLINK X5000R?
The vulnerability ID for TOTOLINK X5000R is CVE-2023-33485.
2
What is the severity of CVE-2023-33485?
The severity of CVE-2023-33485 is high (8.8).
3
What is the affected software for CVE-2023-33485?
The affected software for CVE-2023-33485 is TOTOLINK X5000R with firmware versions 9.1.0u.6118_B20201102 and 9.1.0u.6369_B20230113.
4
How does the vulnerability in TOTOLINK X5000R occur?
The vulnerability in TOTOLINK X5000R occurs due to a post-authentication buffer overflow when the parameter sPort/ePort is used in the addEffect function.
5
Is TOTOLINK X5000R vulnerable to CVE-2023-33485?
Yes, TOTOLINK X5000R with firmware versions 9.1.0u.6118_B20201102 and 9.1.0u.6369_B20230113 is vulnerable to CVE-2023-33485.