VYPR
Unrated severityNVD Advisory· Published Oct 13, 2023· Updated Sep 18, 2024

CVE-2023-45464

CVE-2023-45464

Description

Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the servDomain parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Buffer overflow in Netis N3Mv2 firmware's servDomain parameter allows remote unauthenticated attackers to cause a denial of service.

Vulnerability

A buffer overflow vulnerability exists in the servDomain parameter of the Netis N3Mv2 router firmware version V1.0.1.865. The improper handling of crafted input in this field leads to a buffer overflow, which can be triggered by sending a specially crafted request. The affected firmware is available from the manufacturer's website, and the vulnerability affects the specific build 865 [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted input to the servDomain parameter. No authentication is required, and the attacker can be on the local network or remotely if the management interface is exposed. The crafted input causes a buffer overflow, which leads to the router becoming unresponsive. A proof-of-concept video is referenced by the discoverer [1].

Impact

Successful exploitation results in a Denial of Service (DoS) condition. The router stops functioning, causing network disruption for all connected devices. This effectively disables the router until it is manually rebooted. The vulnerability does not directly lead to code execution or information disclosure based on the available references [1].

Mitigation

As of the publication date (2023-10-13), no official patch or fixed version has been released by Netis. Users are advised to monitor the vendor's website for firmware updates. As a workaround, restrict access to the router's management interface to trusted networks only, and ensure the interface is not exposed to the internet. No workaround within the firmware itself is documented [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Netis/N3Mv2description
  • Netis/N3Mv2llm-fuzzy
    Range: = V1.0.1.865

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.