PT-2023-27970 · Tenda · Tenda Ac9+1

CVE-2023-41552

·

Published

2023-08-30

·

Updated

2023-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC7 version V15.03.06.44 Tenda AC9 version V15.03.06.42 multi
Description A stack overflow issue was discovered, which occurs via the ssid parameter at the "/goform/fast setting wifi set" API endpoint.
Recommendations For Tenda AC7 version V15.03.06.44, avoid using the ssid parameter in the "/goform/fast setting wifi set" API endpoint until the issue is resolved. For Tenda AC9 version V15.03.06.42 multi, avoid using the ssid parameter in the "/goform/fast setting wifi set" API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the "/goform/fast setting wifi set" API endpoint to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-41552

Affected Products

Tenda Ac7
Tenda Ac9