CVE-2023-0782: Tenda AC23 httpd formGetSysToolDDNS out-of-bounds write
A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220640.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0782?
The severity of CVE-2023-0782 is critical with a severity value of 9.8.
How does CVE-2023-0782 affect Tenda AC23?
CVE-2023-0782 affects Tenda AC23 firmware version 16.03.07.45 and leads to an out-of-bounds write vulnerability in the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd.
Can CVE-2023-0782 be exploited remotely?
Yes, CVE-2023-0782 can be exploited remotely.
What is the fix for CVE-2023-0782?
Apply the latest firmware update provided by Tenda to fix the CVE-2023-0782 vulnerability.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-0782?
The Common Weakness Enumeration (CWE) ID for CVE-2023-0782 is CWE-787.