CVE-2023-45985

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 16, 2023
Updated: Oct 19, 2023
CWE ID 787

Summary

CVE-2023-45985 is a stack overflow vulnerability affecting the setParentalRules function in TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 firmwares. Maliciously crafted POST requests can exploit this issue, leading to a Denial of Service (DoS) condition. The vulnerability arises due to insufficient boundary checking in the input validation process, allowing attackers to inject excess data and cause the stack to overflow. This issue poses a significant security risk, as DoS attacks can result in extended downtime, negatively impacting user experience and productivity. Organizations using these TOTOLINK models are advised to apply available patches or updates as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share