PT-2024-14343 · Tenda · Tenda Ax1803

CVE-2023-51958

·

Published

2024-01-10

·

Updated

2024-10-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AX1803 version 1.0.0.1
Description The issue is a stack overflow that occurs via the iptv.stb.port parameter in the formGetIptv() function.
Recommendations For Tenda AX1803 version 1.0.0.1, as a temporary workaround, consider restricting access to the formGetIptv() function until a patch is available. Avoid using the iptv.stb.port parameter in the affected function to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-51958

Affected Products

Tenda Ax1803