CVE-2023-40839: OS Command Injection
Published Aug 30, 2023
·Updated
Tenda AC6 USAC6V1.0BRV15.03.05.16multiTD01.bin function 'subADF3C' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "subADF3C" function to execute commands.
Affected Software
2 affected components
Tenda Ac6 Firmware=15.03.05.16
Tenda AC6=1.0
Event History
Aug 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Tenda AC6 firmware vulnerability?
The vulnerability ID is CVE-2023-40839.
2
What is the severity level of CVE-2023-40839?
The severity level of CVE-2023-40839 is critical.
3
What is the affected software version?
The affected software version is Tenda AC6 firmware version 15.03.05.16.
4
Is Tenda AC6 version 1.0 vulnerable?
No, Tenda AC6 version 1.0 is not vulnerable to CVE-2023-40839.
5
How can I mitigate the CVE-2023-40839 vulnerability?
To mitigate the CVE-2023-40839 vulnerability, update to the latest version of the Tenda AC6 firmware.