CVE-2023-36358: Buffer Overflow
Published Jun 22, 2023
·Updated
TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1 and TL-WR841N V8 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlAccessTargetsRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Affected Software
25 affected components
All of the following
TP-Link Tl-wr940n Firmware
TP-Link TL-WR940N=v4
All of the following
TP-Link TL-WR841N firmware
TP-Link TL-WR841N=v8
All of the following
TP-Link Tl-wr940n Firmware
TP-Link TL-WR940N=v2
All of the following
TP-Link Tl-wr940n Firmware
TP-Link TL-WR940N=v3
All of the following
TP-Link Tl-wr941nd Firmware
TP-Link TL-WR941ND=v5
All of the following
TP-Link Tl-wr941nd Firmware
TP-Link TL-WR941ND=v6
All of the following
TP-Link Tl-wr743nd Firmware
TP-Link TL-WR743ND=v1
TP-Link Tl-wr940n Firmware
TP-Link TL-WR940N=v4
TP-Link TL-WR841N firmware
TP-Link TL-WR841N=v8
TP-Link TL-WR940N=v2
TP-Link TL-WR940N=v3
TP-Link Tl-wr941nd Firmware
TP-Link TL-WR941ND=v5
TP-Link TL-WR941ND=v6
TP-Link Tl-wr743nd Firmware
TP-Link TL-WR743ND=v1
Event History
Jun 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-36358.
2
Which devices are affected by this vulnerability?
TP-Link TL-WR940N V2/V3/V4, TL-WR941ND V5/V6, TL-WR743ND V1, and TL-WR841N V8 are affected by this vulnerability.
3
What is the severity of CVE-2023-36358?
The severity of CVE-2023-36358 is high with a severity value of 7.7.
4
How can this vulnerability be exploited?
Attackers can cause a Denial of Service (DoS) by sending a crafted GET request.
5
Is there a fix available for this vulnerability?
Please refer to the reference link for more information on available fixes.