CVE-2023-36359

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 22, 2023
Updated: Jun 29, 2023
CWE ID 120

Summary

CVE-2023-36359 is a recently disclosed buffer overflow vulnerability affecting various TP-Link models, including TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3, and TL-WR941ND V5/V6. The issue lies within the /userRpm/QoSRuleListRpm component, which can be exploited by attackers to trigger a Denial of Service (DoS) condition. They can achieve this by sending a specially crafted GET request, taking advantage of the buffer overflow and causing the device to crash or become unresponsive. This vulnerability poses a significant risk to network availability and should be addressed promptly by applying the necessary firmware updates provided by TP-Link.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share