CVE-2023-40897: Critical severity Tenda Ac8v4 Firmware vulnerability
Published Aug 24, 2023
·Updated
Tenda AC8 v4 USAC8V4.0siV16.03.34.06cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo.
Affected Software
4 affected components
Tenda Ac8v4 Firmware=16.03.34.06
Tenda AC8V4
All of the following
Tenda Ac8 Firmware=16.03.34.06
Tenda AC8V4
Event History
Aug 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Tenda AC8v4 firmware?
The vulnerability ID for this Tenda AC8v4 firmware is CVE-2023-40897.
2
What is the severity of CVE-2023-40897?
The severity of CVE-2023-40897 is critical with a CVSS score of 9.8.
3
How does CVE-2023-40897 impact the Tenda AC8v4 firmware?
CVE-2023-40897 allows an attacker to trigger a stack overflow via the 'mac' parameter in the '/goform/GetParentControlInfo' endpoint, potentially leading to remote code execution or denial of service.
4
Which version of the Tenda AC8v4 firmware is affected by CVE-2023-40897?
CVE-2023-40897 affects the Tenda AC8v4 firmware version 16.03.34.06.
5
Is Tenda AC8V4 hardware affected by CVE-2023-40897?
No, the Tenda AC8V4 hardware itself is not affected by CVE-2023-40897.