CVE-2023-24096: High severity trendnet tew-820ap vulnerability
UNSUPPORTED WHEN ASSIGNED TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the newpass parameter at /formPasswordSetup. This vulnerability allows attackers to execute arbitrary code via a crafted payload. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24096?
CVE-2023-24096 refers to a vulnerability in the TrendNet Wireless AC Easy-Upgrader TEW-820AP firmware version 1.01.B01 that allows attackers to execute arbitrary code through a stack overflow.
How severe is CVE-2023-24096?
CVE-2023-24096 has a severity value of 8.8, which is considered high.
Which software versions are affected by CVE-2023-24096?
The affected software versions are TrendNet Wireless AC Easy-Upgrader TEW-820AP firmware version 1.01.B01 and TEW-820AP v1.0R.
How can an attacker exploit CVE-2023-24096?
Attackers can exploit CVE-2023-24096 by providing a crafted payload via the 'newpass' parameter at /formPasswordSetup, leading to a stack overflow and potential execution of arbitrary code.
Is there a fix available for CVE-2023-24096?
As of the time of this advisory, there are no known fixes or patches available for CVE-2023-24096. It is recommended to contact the vendor for further information.