CVE-2023-24333: Code Injection
Published Feb 21, 2024
·Updated
A stack overflow vulnerability in Tenda AC21 with firmware version USAC21V1.0reV16.03.08.15cnTDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.
Affected Software
3 affected components
Tenda AC21=US_AC21V1.0re_V16.03.08.15_cn_TDC01
All of the following
Tenda Ac21 Firmware=16.03.08.15
Tenda AC21=1.0
Event History
Feb 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-24333?
The severity of CVE-2023-24333 is rated as high due to its potential to allow remote code execution.
2
How do I fix CVE-2023-24333?
To fix CVE-2023-24333, update the Tenda AC21 firmware to the latest version recommended by the vendor.
3
What systems are affected by CVE-2023-24333?
CVE-2023-24333 affects Tenda AC21 routers running the specific firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01.
4
What type of attack is possible with CVE-2023-24333?
CVE-2023-24333 allows attackers to execute arbitrary commands on the Tenda AC21 router through a crafted POST request.
5
Is there a workaround for CVE-2023-24333?
Currently, the best course of action for CVE-2023-24333 is to upgrade the firmware, as there are no known workarounds.