CVE-2023-36356: High severity TP-Link Tl-wr940n Firmware vulnerability
TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component /userRpm/VirtualServerRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-36356.
Which devices are affected by this vulnerability?
TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 are affected by this vulnerability.
What is the severity of CVE-2023-36356?
The severity of CVE-2023-36356 is high, with a severity value of 7.7.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a crafted GET request to the /userRpm/VirtualServerRpm component, causing a Denial of Service (DoS).
Is there a fix available for CVE-2023-36356?
Currently, there is no information available on a fix for CVE-2023-36356. It is recommended to follow the official advisories and security updates from TP-Link.