CVE-2023-37712: Critical severity Tenda F1202 Firmware vulnerability
Published Jul 10, 2023
·Updated
Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.
Affected Software
12 affected components
All of the following
Tenda F1202 Firmware=1.2.0.20\(408\)
Tenda F1202
All of the following
Tenda Ac1206 Firmware=15.03.06.23
Tenda AC1206
All of the following
Tenda Fh1202 Firmware=1.2.0.20\(408\)
Tenda FH1202
Tenda F1202 Firmware=1.2.0.20\(408\)
Tenda F1202
Tenda Ac1206 Firmware=15.03.06.23
Tenda AC1206
Tenda Fh1202 Firmware=1.2.0.20\(408\)
Tenda FH1202
Event History
Jul 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
05:15 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37712?
The severity of CVE-2023-37712 is critical.
2
What is the vulnerability in Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408)?
The vulnerability in Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) is a stack overflow in the page parameter in the fromSetIpBind function.
3
How can I fix CVE-2023-37712?
To fix CVE-2023-37712, it is recommended to update the affected Tenda AC1206, F1202, and FH1202 devices to the latest firmware version.
4
Where can I find more information about CVE-2023-37712?
More information about CVE-2023-37712 can be found at the following link: https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/fromSetIpBind
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-37712?
The Common Weakness Enumeration (CWE) ID for CVE-2023-37712 is CWE-787.