CVE-2023-33632

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 787

Summary

CVE-2023-33632 is a newly discovered stack overflow vulnerability affecting the H3C Magic R300 router, specifically versions prior to R300-2100MV100R004. This issue can be exploited through the ipqos_lanip_dellist interface located at /goform/aspForm. Successful exploitation could lead to a denial-of-service condition or even remote code execution, posing a significant risk to affected networks. It is recommended that users upgrade to the latest, patched version of their H3C Magic R300 firmware to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share