CVE-2022-41520
published 2022-10-06CVE-2022-41520: TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
PriorityP349high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.91%
57.4th percentile
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| totolink | nr1800x_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TOTOLINK NR1800X 9.1.0u.6279_B20210910 UploadCustomModule File stack-based overflow (EUVD-2022-44713)
vuldb·2026-08-06·CVSS 8.8
CVE-2022-41520 [HIGH] TOTOLINK NR1800X 9.1.0u.6279_B20210910 UploadCustomModule File stack-based overflow (EUVD-2022-44713)
A vulnerability marked as critical has been reported in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this vulnerability is the function UploadCustomModule. The manipulation of the argument File leads to stack-based buffer overflow.
This vulnerability is documented as CVE-2022-41520. The attack requires being on the local network. There is not any exploit available.
GHSA
GHSA-6p6w-2c58-cv5m: TOTOLINK NR1800X V9
ghsa_unreviewed·2022-10-06
CVE-2022-41520 [HIGH] CWE-787 GHSA-6p6w-2c58-cv5m: TOTOLINK NR1800X V9
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule function.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-06
Published