Severity
9.8CRITICAL
EPSS
0.4%
top 37.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7

Description

A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to buffer overflow. VDB-249742 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages2 packages

CVEListV5totolink/x2000r_v22.0.0-B20230727.10434
NVDtotolink/x2000r_firmware2.0.0-b20230727.10434

🔴Vulnerability Details

2
GHSA
GHSA-cvvm-x945-2wwp: A vulnerability classified as critical was found in Totolink X2000R_V2 22024-01-07
CVEList
Totolink X2000R_V2 boa formTmultiAP buffer overflow2024-01-07
CVE-2023-7208 (CRITICAL CVSS 9.8) | A vulnerability classified as criti | cvebase.io