PT-2023-5560 · Tenda · Tenda Ac10
Aixiao0621
·
Published
2023-09-27
·
Updated
2024-09-25
·
CVE-2023-44016
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC10U version 1.0 US AC10UV1.0RTL V15.03.06.49 multi TDE01
Description
The issue is related to a stack overflow in the
addWifiMacFilter function, specifically via the deviceId parameter. This can potentially allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations
For Tenda AC10U version 1.0 US AC10UV1.0RTL V15.03.06.49 multi TDE01, consider disabling the
addWifiMacFilter function until a patch is available to prevent exploitation via the deviceId parameter. Restrict access to this function to minimize the risk of remote attackers leveraging the stack overflow vulnerability.Fix
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac10