CVE-2023-40042: Buffer Overflow
TOTOLINK T10v2 5.9c.5061B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cstemodules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40042?
The severity of CVE-2023-40042 is critical with a CVSS score of 9.8.
What is CVE-2023-40042?
CVE-2023-40042 is a stack-based buffer overflow vulnerability in TOTOLINK T10_v2 firmware version 5.9c.5061_B20200511.
How does CVE-2023-40042 work?
Attackers can exploit CVE-2023-40042 by sending crafted data in an MQTT packet through the comment parameter.
What is the impact of CVE-2023-40042?
CVE-2023-40042 allows attackers to control the return address and execute code on the affected device.
How can I fix CVE-2023-40042?
To fix CVE-2023-40042, update the TOTOLINK T10_v2 firmware to a version that does not have the stack-based buffer overflow vulnerability.