CVE-2023-36340: Critical severity totolink nr1800x firmware vulnerability
Published Oct 16, 2023
·Updated
TOTOLINK NR1800X V9.1.0u.6279B20210910 was discovered to contain a stack overflow via the httphost parameter in the function loginAuth.
Affected Software
2 affected components
TOTOLINK Nr1800x Firmware=9.1.0u.6279_b20210910
TOTOLINK NR1800X
Event History
Oct 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-36340?
CVE-2023-36340 is a vulnerability discovered in TOTOLINK NR1800X V9.1.0u.6279_B20210910 that allows for a stack overflow through the http_host parameter in the loginAuth function.
2
How severe is CVE-2023-36340?
CVE-2023-36340 has a severity rating of 9.8, making it critical.
3
What is the affected software version of CVE-2023-36340?
The affected software version of CVE-2023-36340 is TOTOLINK NR1800X V9.1.0u.6279_B20210910.
4
How can the stack overflow vulnerability be exploited in CVE-2023-36340?
The stack overflow vulnerability in CVE-2023-36340 can be exploited by manipulating the http_host parameter in the loginAuth function.
5
Is TOTOLINK NR1800X V9.1.0u.6279_B20210910 the only vulnerable version?
Yes, TOTOLINK NR1800X V9.1.0u.6279_B20210910 is the only vulnerable version of the software.