PT-2023-6706 · Tenda · Tenda W18E

CVE-2023-46370

·

Publicado

2023-10-24

·

Atualizado

2024-09-17

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda W18E version V16.01.0.8(1576)
Description The issue is related to insufficient argument checking in the formSetNetCheckTools function of the Tenda W18E router's firmware, allowing a remote attacker to execute arbitrary code using the hostName parameter.
Recommendations For Tenda W18E version V16.01.0.8(1576), as a temporary workaround, consider restricting access to the formSetNetCheckTools function until a patch is available. Avoid using the hostName parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07477
CVE-2023-46370

Produtos afetados

Tenda W18E