PT-2023-2938 · Tenda · Tenda Ac6

Funcy_Kilar

·

Published

2023-02-27

·

Updated

2023-04-09

·

CVE-2023-26976

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC6 version 15.03.05.09 multi
Description The issue is related to a stack overflow in the form fast setting wifi set function, specifically via the ssid parameter. This can potentially allow a remote attacker to cause a denial of service. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For Tenda AC6 version 15.03.05.09 multi, consider restricting access to the form fast setting wifi set function until a patch is available. Avoid using the ssid parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-02940
CVE-2023-26976

Affected Products

Tenda Ac6