CVE-2023-31587: Critical severity tenda ac5 firmware vulnerability
Published May 16, 2023
·Updated
Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
Affected Software
4 affected components
All of the following
Tenda Ac5 Firmware=15.03.06.28
Tenda AC5
Tenda Ac5 Firmware=15.03.06.28
Tenda AC5
Remediation
Patch Available
Event History
May 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-31587?
CVE-2023-31587 is a remote code execution (RCE) vulnerability found in the Tenda AC5 router V15.03.06.28.
2
How does the vulnerability in Tenda AC5 router V15.03.06.28 work?
The vulnerability in Tenda AC5 router V15.03.06.28 allows remote attackers to execute arbitrary code by exploiting the Mac parameter at ip/goform/WriteFacMac.
3
What is the severity level of CVE-2023-31587?
CVE-2023-31587 has a severity level of critical.
4
Is Tenda AC5 router V15.03.06.28 the only affected software?
No, Tenda AC5 router V15.03.06.28 is not the only affected software. The Tenda AC5 firmware version 15.03.06.28 is also affected.
5
How can I fix the CVE-2023-31587 vulnerability?
To fix the CVE-2023-31587 vulnerability, update your Tenda AC5 router firmware to a version that addresses the vulnerability.