CVE-2023-40837: OS Command Injection
Tenda AC6 USAC6V1.0BRV15.03.05.16multiTD01.bin function 'subADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "subADD50" function to execute commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40837?
CVE-2023-40837 is a command execution vulnerability in the Tenda AC6 router firmware version 15.03.05.16.
How severe is CVE-2023-40837?
CVE-2023-40837 has a severity rating of 9.8 (Critical).
Which software is affected by CVE-2023-40837?
The Tenda AC6 router firmware version 15.03.05.16 is affected by CVE-2023-40837.
How can I fix CVE-2023-40837?
To fix CVE-2023-40837, update your Tenda AC6 router firmware to a version that is not affected.
Where can I find more information about CVE-2023-40837?
More information about CVE-2023-40837 can be found at the following link: [https://github.com/XYIYM/Digging/blob/main/Tenda/AC6/cmd/2/2.md](https://github.com/XYIYM/Digging/blob/main/Tenda/AC6/cmd/2/2.md)