CVE-2023-24212: Critical severity Tenda AX3 firmware vulnerability
Published Feb 23, 2023
·Updated
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.
Affected Software
2 affected components
Tenda AX3 firmware=16.03.12.11
Tenda AX3
Event History
Feb 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-24212?
CVE-2023-24212 is a vulnerability found in Tenda AX3 V16.03.12.11 firmware that allows a stack overflow via the timeType function at /goform/SetSysTimeCfg.
2
How severe is CVE-2023-24212?
CVE-2023-24212 has a severity rating of critical with a CVSS score of 9.8.
3
How can I fix CVE-2023-24212?
To fix CVE-2023-24212, update your Tenda AX3 firmware to the latest version.
4
Where can I find more information about CVE-2023-24212?
You can find more information about CVE-2023-24212 in the following references: [link1](https://github.com/Venus-WQLab/bug_report/blob/main/Tenda/CVE-2023-24212.md), [link2](https://github.com/w0x68y/cve-lists/blob/main/Tenda/vuln/readme.md).
5
What is the CWE ID for CVE-2023-24212?
The CWE ID for CVE-2023-24212 is 787.