9.8

CVE-2023-38931

Exploit
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tenda ≫ Ac10 Firmware Version 15.03.06.23
   Tenda ≫ Ac10 Version 1.0
Tenda ≫ Ac1206 Firmware Version 15.03.06.23
   Tenda ≫ Ac1206 Version -
Tenda ≫ Ac8 Firmware Version 16.03.34.06
   Tenda ≫ Ac8 Version 4.0
Tenda ≫ Ac6 Firmware Version 15.03.06.23
   Tenda ≫ Ac6 Version 2.0
Tenda ≫ Ac7 Firmware Version 15.03.06.44
   Tenda ≫ Ac7 Version 1.0
Tenda ≫ F1203 Firmware Version 2.0.1.6
   Tenda ≫ F1203 Version -
Tenda ≫ Ac5 Firmware Version 15.03.06.28
   Tenda ≫ Ac5 Version 1.0
Tenda ≫ Ac10 Firmware Version 16.03.10.13
   Tenda ≫ Ac10 Version 4.0
Tenda ≫ Fh1203 Firmware Version 2.0.1.6
   Tenda ≫ Fh1203 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.544
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/cloudv2_setaccount/README.md
Third Party Advisory
Exploit