CVE-2023-37702

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jul 10, 2023
Updated: Jul 13, 2023
CWE ID 787

Summary

CVE-2023-37702: A stack overflow vulnerability was identified in Tenda FH1203 V2.0.1.6. This issue affects the formSetDeviceName function, which can be exploited by sending maliciously crafted deviceId parameters to the device. Successful exploitation could lead to denial of service or even allow attackers to execute arbitrary code with administrative privileges. Users are strongly advised to update their devices to the latest firmware version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share