CVE-2023-38823: Buffer Overflow
Published Nov 20, 2023
·Updated
Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.
Affected Software
10 affected components
All of the following
Tenda Ac6 Firmware=15.03.05.19\(6318\)
Tenda AC6=2.0
All of the following
Tenda Ac6 Firmware=15.03.05.19\(6318\)
Tenda AC6=1.0
All of the following
Tenda Ac9 Firmware=15.03.05.19\(6318\)
Tenda Ac9=1.0
All of the following
Tenda Ac19 Firmware=15.03.05.19\(6318\)
Tenda Ac19=1.0
All of the following
Tenda Ac18 Firmware=15.03.05.19\(6318\)
Tenda Ac18
Event History
Nov 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this buffer overflow vulnerability?
The vulnerability ID for this buffer overflow vulnerability is CVE-2023-38823.
2
What software versions are affected by this vulnerability?
The software versions affected by this vulnerability are Tenda Ac6 Firmware 15.03.05.19(6318), Tenda Ac9 Firmware 15.03.05.19(6318), Tenda Ac19 Firmware 15.03.05.19(6318).
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by executing arbitrary code via the formSetCfm function in bin/httpd.
4
What is the severity level of CVE-2023-38823?
The severity level of CVE-2023-38823 is critical with a score of 9.8.
5
Is there a fix available for this vulnerability?
There is currently no information available about a fix for this vulnerability.