CVE-2023-40845

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 30, 2023
Updated: Sep 7, 2023
CWE ID 787

Summary

CVE-2023-40845 is a newly discovered buffer overflow vulnerability affecting the Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin firmware. The issue lies in the 'sub_34FD0' function where user-supplied data is not properly validated. This leads to a buffer overflow condition, potentially allowing an attacker to execute arbitrary code or cause the device to crash. By sending specially crafted input to the affected system, an adversary can exploit this vulnerability and gain unauthorized access or cause denial-of-service. Users are advised to apply the latest patches or firmware updates to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share