CVE-2023-40798: Input Validation
Published Aug 25, 2023
·Updated
In Tenda AC23 v16.03.07.45cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.
Affected Software
2 affected components
Tenda Ac23 Firmware=16.03.07.45_cn
Tenda AC23
Event History
Aug 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Tenda AC23 vulnerability?
The vulnerability ID for this Tenda AC23 vulnerability is CVE-2023-40798.
2
What is the severity of the vulnerability CVE-2023-40798?
The severity of the vulnerability CVE-2023-40798 is high (8.8).
3
What is the affected software for vulnerability CVE-2023-40798?
The affected software for vulnerability CVE-2023-40798 is Tenda Ac23 Firmware version 16.03.07.45_cn.
4
How does the vulnerability CVE-2023-40798 occur?
The vulnerability CVE-2023-40798 occurs due to the lack of authentication of user input parameters in the formSetIPv6status and formGetWanParameter functions in Tenda AC23 v16.03.07.45_cn.
5
Is Tenda AC23 vulnerable to CVE-2023-40798?
Yes, Tenda AC23 with firmware version 16.03.07.45_cn is vulnerable to CVE-2023-40798.