CVE-2023-24332: High severity tenda ac6 v2.0 vulnerability
Published Feb 21, 2024
·Updated
A stack overflow vulnerability in Tenda AC6 with firmware version USAC6V5.0reV03.03.02.01cnTDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.
Affected Software
3 affected components
Tenda AC6
All of the following
Tenda Ac6 Firmware=03.03.02.01_cn_tdc01
Tenda AC6=5.0
Event History
Feb 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24332?
The severity of CVE-2023-24332 is classified as high due to the potential for arbitrary command execution.
2
How do I fix CVE-2023-24332?
To fix CVE-2023-24332, update the Tenda AC6 firmware to the latest version provided by Tenda that addresses this vulnerability.
3
What devices are affected by CVE-2023-24332?
CVE-2023-24332 affects the Tenda AC6 router with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01.
4
What type of vulnerability is CVE-2023-24332?
CVE-2023-24332 is categorized as a stack overflow vulnerability.
5
What can attackers do with CVE-2023-24332?
Attackers can exploit CVE-2023-24332 to execute arbitrary commands by sending crafted POST requests to the vulnerable router.