CVE-2023-38937
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-38937 affects several Tenda wireless router models, including AC10 v1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi, and AC10 v4.0 V16.03.10.13. The vulnerability arises from a stack overflow in the formSetVirtualSer function due to an issue with the list parameter. An attacker could exploit this flaw by sending specially crafted inputs to the router, potentially leading to a denial-of-service condition or even remote code execution with administrator privileges. Users are advised to update their router firmware as soon as patches become available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd