PT-2023-26612 · Tenda · Tenda Ac18+3
Cao Ngoc Quy
+2
·
Published
2023-11-20
·
Updated
2025-06-10
·
CVE-2023-38823
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda AC19 version 1.0
Tenda AC18 (affected versions not specified)
Tenda AC9 version 1.0
Tenda AC6 versions 1.0 through 2.0
Description
A Buffer Overflow issue allows a remote attacker to execute arbitrary code via the
formSetCfm function in bin/httpd.Recommendations
For Tenda AC19 version 1.0, update to a version that fixes the Buffer Overflow issue in the
formSetCfm function.
For Tenda AC18, apply the necessary patch or update to resolve the Buffer Overflow vulnerability.
For Tenda AC9 version 1.0, update the firmware to address the Buffer Overflow issue.
For Tenda AC6 versions 1.0 through 2.0, apply a patch or update that fixes the Buffer Overflow vulnerability in the formSetCfm function.
As a temporary workaround, consider disabling the formSetCfm function until a patch is available.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Ac18
Tenda Ac19
Tenda Ac6
Tenda Ac9