CVE-2023-40845: Buffer Overflow
Published Aug 30, 2023
·Updated
Tenda AC6 USAC6V1.0BRV15.03.05.16multiTD01.bin is vulnerable to Buffer Overflow via function 'sub34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks.
Affected Software
2 affected components
Tenda Ac6 Firmware=15.03.05.16
Tenda AC6=1.0
Event History
Aug 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Tenda AC6 firmware vulnerability?
The vulnerability ID for this Tenda AC6 firmware vulnerability is CVE-2023-40845.
2
What is the severity level of CVE-2023-40845?
CVE-2023-40845 has a severity level of critical, with a severity value of 9.8.
3
How does this vulnerability occur in Tenda AC6 firmware?
This vulnerability occurs in Tenda AC6 firmware due to a buffer overflow in the 'sub_34FD0' function, where user-provided parameters are read and passed without length checks.
4
Which versions of Tenda AC6 firmware are affected by CVE-2023-40845?
Version 15.03.05.16 of Tenda AC6 firmware is affected by CVE-2023-40845.
5
Is the Tenda AC6 hardware version 1.0 vulnerable to this vulnerability?
No, the Tenda AC6 hardware version 1.0 is not vulnerable to this vulnerability.