CVE-2023-45985
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-45985 is a stack overflow vulnerability affecting the setParentalRules function in TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 firmwares. Maliciously crafted POST requests can exploit this issue, leading to a Denial of Service (DoS) condition. The vulnerability arises due to insufficient boundary checking in the input validation process, allowing attackers to inject excess data and cause the stack to overflow. This issue poses a significant security risk, as DoS attacks can result in extended downtime, negatively impacting user experience and productivity. Organizations using these TOTOLINK models are advised to apply available patches or updates as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- TOTOLINK
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions