VYPR
Critical severity9.8NVD Advisory· Published Aug 14, 2023· Updated Jun 17, 2026

CVE-2023-29468

CVE-2023-29468

Description

The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a management frame. Using a specially crafted frame, a buffer overflow can be triggered that can potentially lead to remote code execution. This affects WILINK8-WIFI-MCP8 version 8.5_SP3 and earlier.

Affected products

5
  • cpe:2.3:a:ti:wilink8-wifi-mcp8:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ti:wilink8-wifi-mcp8:*:*:*:*:*:*:*:*range: <8.5
    • cpe:2.3:a:ti:wilink8-wifi-mcp8:8.5:-:*:*:*:*:*:*
    • cpe:2.3:a:ti:wilink8-wifi-mcp8:8.5:sp3:*:*:*:*:*:*
  • Texas Instruments/WiLink WL18xx MCP driverdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.