Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
References
Link | Resource |
---|---|
https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetVirtualSer/README.md | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
10 Aug 2023, 18:22
Type | Values Removed | Values Added |
---|---|---|
First Time |
Tenda ac1206 Firmware
Tenda ac5 Tenda ac10 Tenda ac5 Firmware Tenda ac7 Firmware Tenda ac1206 Tenda ac7 Tenda ac9 Tenda ac6 Tenda Tenda ac8 Firmware Tenda ac9 Firmware Tenda ac6 Firmware Tenda ac10 Firmware Tenda ac8 |
|
References | (MISC) https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetVirtualSer/README.md - Exploit, Third Party Advisory | |
CWE | CWE-787 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac9:3.0:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac5:1.0:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac10:1.0:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac8:4.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac10_firmware:16.03.10.13:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac10_firmware:15.03.06.23:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac10:4.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac9_firmware:15.03.06.42_multi:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac5_firmware:15.03.06.28:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac8_firmware:16.03.34.06:*:*:*:*:*:*:* |
07 Aug 2023, 19:30
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-07 19:15
Updated : 2023-12-10 15:14
NVD link : CVE-2023-38937
Mitre link : CVE-2023-38937
CVE.ORG link : CVE-2023-38937
JSON object : View
Products Affected
tenda
- ac6_firmware
- ac7
- ac1206_firmware
- ac5_firmware
- ac8
- ac6
- ac9
- ac10_firmware
- ac7_firmware
- ac1206
- ac10
- ac9_firmware
- ac8_firmware
- ac5
CWE
CWE-787
Out-of-bounds Write