CVE-2023-36355

CRITICAL ⚠ Exploit

TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) v...

Affects 2 products across 1 vendor.

BCS8.88
CVSS 3.19.9
EPSS31.7%
Percentile98th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-120: Buffer Copy without Checking Size (Classic Buffer Overflow)

Program copies data to a buffer without verifying the source data fits within the destination.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-120
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-120
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-120
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-120
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-120
Show all 13

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical buffer overflow vulnerability exists in the TP-Link TL-WR940N V4 router, affecting the ipStart parameter at /userRpm/WanDynamicIpV6Cfg and /userRpm/WanDynamicIpV6CfgRpm endpoints. This can be exploited to cause a Denial of Service (DoS) via a crafted GET request.

BSID: BS-2023-GLOBAL-156805-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-36355?
A critical buffer overflow vulnerability exists in the TP-Link TL-WR940N V4 router, affecting the ipStart parameter at /userRpm/WanDynamicIpV6Cfg and /userRpm/WanDynamicIpV6CfgRpm endpoints. This can be exploited to cause a Denial of Service (DoS) via a crafted GET request.
What is the CVSS score for CVE-2023-36355?
CVE-2023-36355 has CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. EPSS: 31.7%.
Is CVE-2023-36355 actively exploited?
Public exploit available for CVE-2023-36355. Exploitation risk elevated.
How do I remediate CVE-2023-36355?
Priority: IMMEDIATE.
What systems are affected by CVE-2023-36355?
CVE-2023-36355 affects: Tp-Link, Tp-Link.
Vulnerability Details
CVE IDCVE-2023-36355
BSIDBS-2023-GLOBAL-156805-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published2023-06-22
Last Modified2024-11-21
ICS Relevance90%
Weakness (CWE)
SourceNVD
Official Description

TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by sending a specially crafted GET request to the /userRpm/WanDynamicIpV6Cfg or /userRpm/WanDynamicIpV6CfgRpm endpoints with an overly long value for the ipStart parameter, leading to a buffer overflow.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Tp-Link Tl-Wr940N Firmware
Tp-Link Tl-Wr940N
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 1142 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Tp-Link
CVE-2013-2578 10.0 cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC317... CVE-2013-2579 10.0 TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly... CVE-2024-25139 10.0 In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susc... CVE-2017-8220 9.9 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 R... CVE-2023-31710 9.8 TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build...
View all Tp-Link CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →