PT-2023-30699 · Tenda · Tenda Ax1803

Published

2023-11-20

·

Updated

2023-11-24

·

CVE-2023-48109

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda AX1803 version 1.0.0.1
Description A heap overflow issue was discovered, allowing attackers to cause a Denial of Service (DoS) attack via the deviceId parameter in the saveParentControlInfo() function.
Recommendations For Tenda AX1803 version 1.0.0.1, consider disabling the saveParentControlInfo() function until a patch is available to prevent potential Denial of Service (DoS) attacks. Avoid using the deviceId parameter in the affected function to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2023-48109

Affected Products

Tenda Ax1803