PT-2023-5285 · Tenda · Tenda Ac10V4

Published

2023-09-08

·

Updated

2023-09-21

·

CVE-2023-42320

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC10V4 version US AC10V4.0si V16.03.10.13 cn TDC01
Description The issue is related to a buffer overflow in the GetParentControlInfo function when handling the mac parameter, allowing a remote attacker to cause a denial of service or potentially execute arbitrary code.
Recommendations For Tenda AC10V4 version US AC10V4.0si V16.03.10.13 cn TDC01, consider disabling the GetParentControlInfo() function until a patch is available to prevent exploitation via the mac parameter. Restrict access to the vulnerable function to minimize the risk of denial of service or code execution.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-05909
CVE-2023-42320

Affected Products

Tenda Ac10V4