First published: Wed Aug 30 2023(Updated: )
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ac6 Firmware | =15.03.05.16 | |
Tenda AC6 | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40837 is a command execution vulnerability in the Tenda AC6 router firmware version 15.03.05.16.
CVE-2023-40837 has a severity rating of 9.8 (Critical).
The Tenda AC6 router firmware version 15.03.05.16 is affected by CVE-2023-40837.
To fix CVE-2023-40837, update your Tenda AC6 router firmware to a version that is not affected.
More information about CVE-2023-40837 can be found at the following link: [https://github.com/XYIYM/Digging/blob/main/Tenda/AC6/cmd/2/2.md](https://github.com/XYIYM/Digging/blob/main/Tenda/AC6/cmd/2/2.md)