CVE-2023-38933: Critical severity Tenda Ac10 Firmware vulnerability
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-38933.
Which devices are affected by CVE-2023-38933?
Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) are affected by CVE-2023-38933.
What is the severity of CVE-2023-38933?
CVE-2023-38933 has a severity of critical with a CVSS score of 9.8.
How does CVE-2023-38933 impact the devices?
CVE-2023-38933 allows an attacker to trigger a stack overflow via the deviceId parameter in the formSetClientState function.
Is there a fix available for CVE-2023-38933?
There is currently no fix available for CVE-2023-38933. It is recommended to update to the latest firmware version once a fix is released.