CVE-2023-37702
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jul 10, 2023
Updated: Jul 13, 2023
CWE ID 787
Summary
CVE-2023-37702: A stack overflow vulnerability was identified in Tenda FH1203 V2.0.1.6. This issue affects the formSetDeviceName function, which can be exploited by sending maliciously crafted deviceId parameters to the device. Successful exploitation could lead to denial of service or even allow attackers to execute arbitrary code with administrative privileges. Users are strongly advised to update their devices to the latest firmware version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd