First published: Sat Feb 11 2023(Updated: )
A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220640.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ac23 Firmware | =16.03.07.45 | |
Tenda AC23 | ||
All of | ||
Tenda Ac23 Firmware | =16.03.07.45 | |
Tenda AC23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0782 is critical with a severity value of 9.8.
CVE-2023-0782 affects Tenda AC23 firmware version 16.03.07.45 and leads to an out-of-bounds write vulnerability in the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd.
Yes, CVE-2023-0782 can be exploited remotely.
Apply the latest firmware update provided by Tenda to fix the CVE-2023-0782 vulnerability.
The Common Weakness Enumeration (CWE) ID for CVE-2023-0782 is CWE-787.