PT-2023-27974 · Tenda · Tenda Ac9+2

Published

2023-08-30

·

Updated

2023-08-31

·

CVE-2023-41556

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC7 version 1.0 V15.03.06.44 Tenda AC9 version 3.0 V15.03.06.42 multi Tenda AC5 version 1.0RTL V15.03.06.28
Description A stack overflow issue was discovered via the parameter list at the "/goform/SetIpMacBind" API endpoint. This issue affects certain Tenda router models.
Recommendations For Tenda AC7 version 1.0 V15.03.06.44, avoid using the parameter list at the "/goform/SetIpMacBind" API endpoint until a patch is available. For Tenda AC9 version 3.0 V15.03.06.42 multi, restrict access to the "/goform/SetIpMacBind" API endpoint to minimize the risk of exploitation. For Tenda AC5 version 1.0RTL V15.03.06.28, consider disabling the functionality related to the "/goform/SetIpMacBind" API endpoint as a temporary workaround.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-41556

Affected Products

Tenda Ac5
Tenda Ac7
Tenda Ac9