CVE-2023-34571: Medium severity Tenda Ac10 Firmware vulnerability
Published Jun 8, 2023
·Updated
Tenda AC10 v4 USAC10V4.0siV16.03.10.13cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.
Affected Software
4 affected components
Tenda Ac10 Firmware=us_ac10v4.0si_v16.03.10.13_cn
Tenda AC10=4.0
All of the following
Tenda Ac10 Firmware=us_ac10v4.0si_v16.03.10.13_cn
Tenda AC10=4.0
Event History
Jun 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34571?
CVE-2023-34571 is a vulnerability discovered in the Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn firmware, which allows for a stack overflow through the shareSpeed parameter in the /goform/WifiGuestSet endpoint.
2
How severe is CVE-2023-34571?
CVE-2023-34571 has a severity rating of medium (6.7).
3
What software is affected by CVE-2023-34571?
The Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn firmware is affected by CVE-2023-34571.
4
How can the stack overflow vulnerability in CVE-2023-34571 be exploited?
The stack overflow vulnerability in CVE-2023-34571 can be exploited by sending a specially crafted value for the shareSpeed parameter in the /goform/WifiGuestSet endpoint.
5
Is the Tenda AC10 router version 4.0 affected by CVE-2023-34571?
No, the Tenda AC10 router version 4.0 is not affected by CVE-2023-34571.