PT-2023-5285 · Tenda · Tenda Ac10V4
Published
2023-09-08
·
Updated
2023-09-21
·
CVE-2023-42320
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda AC10V4 version US AC10V4.0si V16.03.10.13 cn TDC01
Description
The issue is related to a buffer overflow in the GetParentControlInfo function when handling the
mac parameter, allowing a remote attacker to cause a denial of service or potentially execute arbitrary code.Recommendations
For Tenda AC10V4 version US AC10V4.0si V16.03.10.13 cn TDC01, consider disabling the
GetParentControlInfo() function until a patch is available to prevent exploitation via the mac parameter. Restrict access to the vulnerable function to minimize the risk of denial of service or code execution.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac10V4