CVE-2023-40841

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 30, 2023
Updated: Sep 7, 2023
CWE ID 787

Summary

CVE-2023-40841 refers to a buffer overflow vulnerability in the Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin firmware. The issue lies within the "add_white_node" function, which can be exploited to write past the intended buffer boundary. Successful exploitation could allow an attacker to execute arbitrary code or cause the device to crash, potentially leading to denial-of-service conditions or more serious compromise. It is essential for users of affected devices to install the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share