PT-2023-5560 · Tenda · Tenda Ac10
Aixiao0621
·
Publicado
2023-09-27
·
Atualizado
2024-09-25
·
CVE-2023-44016
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC10U version 1.0 US AC10UV1.0RTL V15.03.06.49 multi TDE01
Description
The issue is related to a stack overflow in the
addWifiMacFilter function, specifically via the deviceId parameter. This can potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations
For Tenda AC10U version 1.0 US AC10UV1.0RTL V15.03.06.49 multi TDE01, consider disabling the
addWifiMacFilter function until a patch is available to prevent exploitation via the deviceId parameter. Restrict access to this function to minimize the risk of remote attackers leveraging the stack overflow vulnerability.Correção
Stack Overflow
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tenda Ac10