CVE-2023-36947: Critical severity totolink x5000r firmware vulnerability
Published Oct 16, 2023
·Updated
TOTOLINK X5000R V9.1.0u.6118B20201102 and TOTOLINK A7000R V9.1.0u.6115B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
Affected Software
8 affected components
All of the following
TOTOLINK X5000R
TOTOLINK X5000r Firmware=9.1.0u.6118_b20201102
All of the following
TOTOLINK A7000R
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK X5000r Firmware=9.1.0u.6118_b20201102
TOTOLINK X5000R
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
Event History
Oct 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this TOTOLINK firmware issue?
The vulnerability ID for this TOTOLINK firmware issue is CVE-2023-36947.
2
What is the severity level of CVE-2023-36947?
The severity level of CVE-2023-36947 is critical.
3
Which TOTOLINK firmware versions are affected by CVE-2023-36947?
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 are affected by CVE-2023-36947.
4
What is the cause of the vulnerability in TOTOLINK firmware?
The vulnerability in TOTOLINK firmware is caused by a stack overflow in the File parameter of the UploadCustomModule function.
5
Is there a fix available for CVE-2023-36947?
Yes, a fix is available for CVE-2023-36947. It is recommended to update to the latest firmware version provided by TOTOLINK.