CVE-2023-36950: Critical severity totolink x5000r firmware vulnerability
Published Oct 16, 2023
·Updated
TOTOLINK X5000R V9.1.0u.6118B20201102 and TOTOLINK A7000R V9.1.0u.6115B20201022 was discovered to contain a stack overflow via the httphost parameter in the function loginAuth.
Affected Software
8 affected components
TOTOLINK X5000r Firmware=9.1.0u.6118_b20201102
TOTOLINK X5000R
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
All of the following
TOTOLINK X5000r Firmware=9.1.0u.6118_b20201102
TOTOLINK X5000R
All of the following
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
Event History
Oct 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-36950?
The severity of CVE-2023-36950 is critical.
2
What is the affected software for CVE-2023-36950?
The affected software for CVE-2023-36950 is TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022.
3
How does CVE-2023-36950 exploit the vulnerability?
CVE-2023-36950 exploits the vulnerability through the http_host parameter in the function loginAuth.
4
Is TOTOLINK X5000R V9.1.0u.6118_B20201102 vulnerable to CVE-2023-36950?
Yes, TOTOLINK X5000R V9.1.0u.6118_B20201102 is vulnerable to CVE-2023-36950.
5
Is TOTOLINK A7000R V9.1.0u.6115_B20201022 vulnerable to CVE-2023-36950?
Yes, TOTOLINK A7000R V9.1.0u.6115_B20201022 is vulnerable to CVE-2023-36950.