PT-2023-27697 · Tenda · Tenda Ax3

Korey0Sh1

·

Published

2023-08-25

·

Updated

2023-08-29

·

CVE-2023-40915

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda AX3 version 16.03.12.11
Description The issue is a stack buffer overflow that allows attackers to cause a Denial of Service (DoS) via the ssid parameter. This occurs at the form fast setting wifi set function.
Recommendations For Tenda AX3 version 16.03.12.11, as a temporary workaround, consider restricting access to the form fast setting wifi set function until a patch is available. Avoid using the ssid parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-40915

Affected Products

Tenda Ax3