First published: Sun Sep 03 2023(Updated: )
A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238633 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ac8 Firmware | =16.03.34.06 | |
Tenda AC8 | =4.0 | |
All of | ||
=16.03.34.06 | ||
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4744 is a critical vulnerability found in Tenda AC8 16.03.34.06_cn_TDC01 firmware, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a long device name.
The severity of CVE-2023-4744 is critical, with a CVSS score of 9.8 out of 10.
CVE-2023-4744 affects the function formSetDeviceName in Tenda AC8, allowing remote exploitation to execute arbitrary code or cause a denial of service.
Yes, Tenda AC8 firmware version 16.03.34.06 is vulnerable to CVE-2023-4744.
To mitigate the vulnerability in Tenda AC8, it is recommended to update to a patched firmware version provided by the vendor.