PT-2023-30072 · Totolink · Totolink X2000R

Published

2023-10-25

·

Updated

2024-09-11

·

CVE-2023-46542

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X2000R Gh version 1.0.0-B20230221.0948.web
Description A stack overflow issue was discovered via the function formMeshUploadConfig(). This issue may allow for exploitation, potentially leading to unintended consequences. However, no information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For TOTOLINK X2000R Gh version 1.0.0-B20230221.0948.web, as a temporary workaround, consider disabling the formMeshUploadConfig() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-46542

Affected Products

Totolink X2000R