CVE-2023-40847: Buffer Overflow
Published Aug 30, 2023
·Updated
Tenda AC6 USAC6V1.0BRV15.03.05.16multiTD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check.
Affected Software
2 affected components
Tenda Ac6 Firmware=15.03.05.16
Tenda AC6=1.0
Event History
Aug 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Tenda AC6 firmware vulnerability?
The vulnerability ID is CVE-2023-40847.
2
What is the severity level of CVE-2023-40847?
The severity level of CVE-2023-40847 is critical with a score of 9.8.
3
What is the affected software of this vulnerability?
The affected software is Tenda Ac6 Firmware version 15.03.05.16.
4
How does the vulnerability occur in Tenda AC6 firmware?
The vulnerability occurs due to a buffer overflow in the function "initIpAddrInfo" where a user-provided parameter is passed without any length check.
5
Is Tenda AC6 version 1.0 affected by this vulnerability?
No, Tenda AC6 version 1.0 is not affected by this vulnerability.