PT-2023-6706 · Tenda · Tenda W18E

Published

2023-10-24

·

Updated

2024-09-17

·

CVE-2023-46370

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda W18E version V16.01.0.8(1576)
Description The issue is related to insufficient argument checking in the formSetNetCheckTools function of the Tenda W18E router's firmware, allowing a remote attacker to execute arbitrary code using the hostName parameter.
Recommendations For Tenda W18E version V16.01.0.8(1576), as a temporary workaround, consider restricting access to the formSetNetCheckTools function until a patch is available. Avoid using the hostName parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-07477
CVE-2023-46370

Affected Products

Tenda W18E