PT-2022-6754 · Tenda · Tenda Ac1206+5

Published

2022-06-29

·

Updated

2023-07-21

·

CVE-2023-37716

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda F1202 version V1.0BR V1.2.0.20(408) Tenda FH1202 version V1.2.0.19 EN Tenda AC10 version V1.0 Tenda AC1206 version V1.0 Tenda AC7 version V1.0 Tenda AC5 version V1.0 Tenda AC9 version V3.0
Description The issue is related to a stack overflow in the fromNatStaticSetting() function when processing the page parameter, potentially allowing a remote attacker to execute arbitrary code or cause a denial of service by sending a specially crafted request.
Recommendations For Tenda F1202 version V1.0BR V1.2.0.20(408), consider disabling the fromNatStaticSetting() function until a patch is available. For Tenda FH1202 version V1.2.0.19 EN, restrict access to the fromNatStaticSetting() function to minimize the risk of exploitation. For Tenda AC10 version V1.0, Tenda AC1206 version V1.0, Tenda AC7 version V1.0, Tenda AC5 version V1.0, and Tenda AC9 version V3.0, avoid using the page parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-03884
CVE-2023-37716

Affected Products

Tenda Ac10
Tenda Ac1206
Tenda Ac5
Tenda Ac7
Tenda Ac9
Tenda Fh1202