CRITICAL · 9.8

CVE-2023-38931

Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 ...

Vulnerability Description

Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
TendaAc10 Firmware15.03.06.23
TendaAc101.0
TendaAc1206 Firmware15.03.06.23
TendaAc1206-
TendaAc8 Firmware16.03.34.06
TendaAc84.0
TendaAc6 Firmware15.03.06.23
TendaAc62.0
TendaAc7 Firmware15.03.06.44
TendaAc71.0
TendaF1203 Firmware2.0.1.6
TendaF1203-
TendaAc5 Firmware15.03.06.28
TendaAc51.0
TendaFh1203 Firmware2.0.1.6
TendaFh1203-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-38931?

CVE-2023-38931 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 ...

How severe is CVE-2023-38931?

CVE-2023-38931 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-38931?

Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac10 Firmware, Tenda Ac10, Tenda Ac1206 Firmware, Tenda Ac1206, Tenda Ac8 Firmware.