CVE-2024-10123: Tenda AC8 saveParentControlInfo compare_parentcontrol_time stack-based overflow
A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. Affected by this vulnerability is the function compareparentcontroltime of the file /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This is not the same issue like CVE-2023-33671. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10123?
CVE-2024-10123 is classified as a critical severity vulnerability.
How do I fix CVE-2024-10123?
To fix CVE-2024-10123, update the Tenda AC8 firmware to a version that is not affected by this vulnerability.
What type of vulnerability is CVE-2024-10123?
CVE-2024-10123 is a stack-based buffer overflow vulnerability.
Which software version is affected by CVE-2024-10123?
CVE-2024-10123 affects Tenda AC8 firmware version 16.03.34.06.
What function is vulnerable in CVE-2024-10123?
The function compare_parentcontrol_time in the file /goform/saveParentControlInfo is vulnerable in CVE-2024-10123.