CVE-2023-40898: Critical severity Tenda Ac8v4 Firmware vulnerability
Published Aug 24, 2023
·Updated
Tenda AC8 v4 USAC8V4.0siV16.03.34.06cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.
Affected Software
4 affected components
Tenda Ac8v4 Firmware=16.03.34.06
Tenda AC8V4
All of the following
Tenda Ac8 Firmware=16.03.34.06
Tenda AC8V4
Event History
Aug 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-40898?
CVE-2023-40898 is a vulnerability found in Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn firmware, which allows for a stack overflow via the timeZone parameter in /goform/SetSysTimeCfg.
2
How severe is CVE-2023-40898?
CVE-2023-40898 has a severity level of critical with a CVSS score of 9.8.
3
What software versions are affected by CVE-2023-40898?
The Tenda AC8 v4 firmware version 16.03.34.06 is affected by CVE-2023-40898.
4
How can I fix CVE-2023-40898?
To fix CVE-2023-40898, it is recommended to update the Tenda AC8 v4 firmware to a non-vulnerable version provided by the vendor.
5
Where can I find more information about CVE-2023-40898?
More information about CVE-2023-40898 can be found at the following reference: https://github.com/peris-navince/founded-0-days/blob/main/ac8/SetSysTimeCfg/1.md