CVE-2023-38935: Critical severity tenda ac1206 firmware vulnerability
Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38935?
CVE-2023-38935 is a vulnerability found in Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13, and AC9 V3.0 V15.03.06.42_multi that allows for a stack overflow via the list parameter in the formSetQosBand function.
What is the severity of CVE-2023-38935?
CVE-2023-38935 has a severity rating of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2023-38935?
The affected software versions are Tenda AC1206 Firmware 15.03.06.23, Tenda AC5 Firmware 15.03.06.28, Tenda AC9 Firmware 15.03.06.42_multi, Tenda AC8 Firmware 16.03.34.06, and Tenda AC10 Firmware 16.03.10.13.
How can I fix CVE-2023-38935?
To fix CVE-2023-38935, it is recommended to update to the latest firmware version provided by Tenda.
Where can I find more information about CVE-2023-38935?
More information about CVE-2023-38935 can be found at the following reference: [link](https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetQosBand/README.md)