9.8
CVSSv3

CVE-2023-40041

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00286 | KEV: Not Included
Published: 08/08/2023 Updated: 21/11/2024

Vulnerability Summary

TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code.

Vulnerable Product Search on Vulmon Subscribe to Product

totolink t10 v2 -

totolink t10 v2 firmware 5.9c.5061 b20200511

Vendor Advisories

Check Point Reference: CPAI-2023-1594 Date Published: 24 Mar 2024 Severity: Critical ...