Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
References
Link | Resource |
---|---|
https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetSpeedWan/README.md | Exploit Vendor Advisory |
https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetSpeedWan/README.md | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
21 Nov 2024, 08:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetSpeedWan/README.md - Exploit, Vendor Advisory |
10 Aug 2023, 18:20
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:tenda:ac9_firmware:15.03.06.42_multi:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac5_firmware:15.03.06.28:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac10_firmware:15.03.06.23:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:* cpe:2.3:h:tenda:f1203:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1203_firmware:2.0.1.6:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1205_firmware:2.0.0.7\(775\):*:*:*:*:*:*:* cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:fh1205:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac5:1.0:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac9:3.0:*:*:*:*:*:*:* cpe:2.3:h:tenda:fh1203:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac10:1.0:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:f1203_firmware:2.0.1.6:*:*:*:*:*:*:* |
|
First Time |
Tenda fh1205 Firmware
Tenda ac7 Firmware Tenda ac9 Tenda Tenda ac6 Tenda ac5 Firmware Tenda ac7 Tenda fh1203 Tenda ac10 Tenda f1203 Tenda ac1206 Tenda ac6 Firmware Tenda ac1206 Firmware Tenda ac9 Firmware Tenda f1203 Firmware Tenda fh1205 Tenda ac5 Tenda ac10 Firmware Tenda fh1203 Firmware |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-787 | |
References | (MISC) https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetSpeedWan/README.md - Exploit, Vendor Advisory |
07 Aug 2023, 19:30
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-07 19:15
Updated : 2024-11-21 08:14
NVD link : CVE-2023-38936
Mitre link : CVE-2023-38936
CVE.ORG link : CVE-2023-38936
JSON object : View
Products Affected
tenda
- ac9_firmware
- ac9
- ac1206
- ac7_firmware
- ac7
- fh1205_firmware
- fh1203
- ac10
- ac5
- ac6
- fh1205
- ac6_firmware
- fh1203_firmware
- ac1206_firmware
- ac5_firmware
- f1203
- f1203_firmware
- ac10_firmware
CWE
CWE-787
Out-of-bounds Write