CVE-2023-33643

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 787

Summary

CVE-2023-33643 is a newly discovered stack overflow vulnerability affecting the H3C Magic R300 router in its R300-2100MV100R004 firmware. This issue can be exploited by sending maliciously crafted traffic to the AddWlanMacList interface located at /goform/aspForm. Successful exploitation may lead to a denial-of-service condition or potentially more serious consequences, such as remote code execution, depending on the specific attack vector employed. Users are strongly advised to apply the relevant software patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share