CVE-2023-36103: Command Injection
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36103?
CVE-2023-36103 has been classified as a high severity vulnerability due to its ability to allow remote command execution.
How can I mitigate CVE-2023-36103?
To mitigate CVE-2023-36103, it is recommended to update Tenda AC15 firmware to the latest version that addresses this vulnerability.
What devices are affected by CVE-2023-36103?
CVE-2023-36103 specifically affects the Tenda AC15 with firmware version 15.03.05.20.
What type of vulnerability is CVE-2023-36103?
CVE-2023-36103 is a command injection vulnerability that allows attackers to execute arbitrary commands remotely.
How does CVE-2023-36103 work?
CVE-2023-36103 works by accepting crafted POST requests at the goform/SetIPTVCfg interface, which can inject commands into the system.