CVE-2023-33640

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 787

Summary

CVE-2023-33640 refers to a stack overflow vulnerability found in H3C Magic R300 routers running version R300-2100MV100R004. This issue can be exploited through the SetAPWifiorLedInfoById interface located at /goform/aspForm. A stack overflow occurs when a program tries to allocate more memory to a stack than is available, potentially leading to the crash of the application or the operating system. Successful exploitation of this vulnerability could result in denial-of-service attacks or even remote code execution, posing a significant threat to the affected network infrastructure. Users are advised to update their software to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share