CVE-2023-41561: Critical severity tenda ac9 vulnerability
Published Aug 30, 2023
·Updated
Tenda AC9 V3.0 V15.03.06.42multi and Tenda AC5 USAC5V1.0RTLV15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.
Affected Software
4 affected components
Tenda Ac9 Firmware=15.03.06.42_multi
Tenda Ac9=3.0
Tenda Ac5 Firmware=15.03.06.28
Tenda AC5=1.0
Event History
Aug 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Tenda AC9 and AC5 issue?
The vulnerability ID is CVE-2023-41561.
2
What is the severity rating of CVE-2023-41561?
The severity rating of CVE-2023-41561 is critical (9.8).
3
Which Tenda devices are affected by CVE-2023-41561?
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 are affected by CVE-2023-41561.
4
What is the cause of CVE-2023-41561?
CVE-2023-41561 is caused by a stack overflow via the parameter startIp and endIp at the URL /goform/SetPptpServerCfg.
5
Is there a fix available for CVE-2023-41561?
At the moment, there is no information available regarding a fix for CVE-2023-41561. It is recommended to follow the vendor's security advisories for any updates.