CVE-2023-38937: Critical severity Tenda Ac10 Firmware vulnerability
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38937?
CVE-2023-38937 is a vulnerability found in Tenda AC10, AC1206, AC8, AC6, AC7, AC5, and AC9 routers that allows for a stack overflow via the list parameter in the formSetVirtualSer function.
What is the severity of CVE-2023-38937?
The severity of CVE-2023-38937 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2023-38937?
The affected software versions are Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi, and AC10 v4.0 V16.03.10.13.
How can I fix CVE-2023-38937?
To fix CVE-2023-38937, it is recommended to update your Tenda router to the latest firmware version provided by the manufacturer.
Where can I find more information about CVE-2023-38937?
You can find more information about CVE-2023-38937 on the GitHub page of the IoT-Vulns project.