CVE-2023-4744: Tenda AC8 formSetDeviceName stack-based overflow
A vulnerability was found in Tenda AC8 16.03.34.06cnTDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238633 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4744?
CVE-2023-4744 is a critical vulnerability found in Tenda AC8 16.03.34.06_cn_TDC01 firmware, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a long device name.
What is the severity of CVE-2023-4744?
The severity of CVE-2023-4744 is critical, with a CVSS score of 9.8 out of 10.
How does CVE-2023-4744 affect Tenda AC8?
CVE-2023-4744 affects the function formSetDeviceName in Tenda AC8, allowing remote exploitation to execute arbitrary code or cause a denial of service.
Is Tenda AC8 firmware version 16.03.34.06 vulnerable to CVE-2023-4744?
Yes, Tenda AC8 firmware version 16.03.34.06 is vulnerable to CVE-2023-4744.
How do I mitigate the vulnerability in Tenda AC8?
To mitigate the vulnerability in Tenda AC8, it is recommended to update to a patched firmware version provided by the vendor.