CVE-2023-49418: Critical severity zioncom a7000r firmware vulnerability
Published Dec 11, 2023
·Updated
TOTOLink A7000R V9.1.0u.6115B20201022has a stack overflow vulnerability via setIpPortFilterRules.
Affected Software
2 affected components
All of the following
TOTOLINK A7000R firmware=9.1.0u.6115_b20201022
TOTOLINK A7000R
Event History
Dec 11, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49418?
CVE-2023-49418 has been classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2023-49418?
To fix CVE-2023-49418, update the TOTOLink A7000R firmware to the latest version provided by the vendor.
3
What does CVE-2023-49418 affect?
CVE-2023-49418 affects specific firmware version 9.1.0u.6115_B20201022 of the TOTOLink A7000R router.
4
What is the nature of the vulnerability in CVE-2023-49418?
CVE-2023-49418 is a stack overflow vulnerability that can be exploited through the setIpPortFilterRules function.
5
How can CVE-2023-49418 be exploited?
CVE-2023-49418 can be exploited remotely by sending crafted requests to the affected device's setIpPortFilterRules endpoint.