CVE-2023-33485

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 787

Summary

CVE-2023-33485 is a recently disclosed vulnerability affecting the TOTOLINK X5000R routers with firmware versions V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113. This flaw involves a post-authentication buffer overflow issue in the addEffect function, which can be triggered through the sPort/ePort parameter. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code, potentially leading to unauthorized access, data theft, or system compromise. Users are strongly advised to update their firmware as soon as possible to minimize the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share