First published: Tue Nov 07 2023(Updated: )
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
=1.0.0.1 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47455 is a heap overflow vulnerability in the Tenda AX1806 V1.0.0.1 firmware, specifically in the setSchedWifi function.
The CVE-2023-47455 vulnerability occurs when the src and v12 parameters obtained from the HTTP request are not properly checked for their size, leading to a heap overflow.
The severity of CVE-2023-47455 is critical, with a CVSS score of 9.1.
The Tenda AX1806 firmware version 1.0.0.1 is affected by CVE-2023-47455.
No, the Tenda AX1806 hardware itself is not vulnerable to CVE-2023-47455, only the firmware version 1.0.0.1.