PT-2023-9046 · Tenda · Tenda Fh1202+2

Publicado

2023-07-13

·

Atualizado

2023-07-21

·

CVE-2023-37714

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda F1202 version V1.0BR V1.2.0.20(408) Tenda FH1202 version V1.2.0.19 EN Tenda AC7 (affected versions not specified) Tenda PW201A (affected versions not specified)
Description A stack overflow issue was discovered in the fromRouteStatic function when handling the page parameter. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Tenda F1202 version V1.0BR V1.2.0.20(408), consider disabling the fromRouteStatic function until a patch is available. For Tenda FH1202 version V1.2.0.19 EN, restrict access to the page parameter in the affected function to minimize the risk of exploitation. For Tenda AC7 and Tenda PW201A, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-03254
CVE-2023-37714

Produtos afetados

Tenda Ac7
Tenda Fh1202
Tenda Pw201A