CVE-2023-40847
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Aug 30, 2023
Updated: Sep 7, 2023
CWE ID 787
Summary
CVE-2023-40847 is a buffer overflow vulnerability affecting Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin. The issue lies within the "initIpAddrInfo" function, which fails to implement proper length checks on user-supplied data. As a result, an attacker can exploit this vulnerability by overwriting adjacent memory, potentially leading to code injection or arbitrary code execution. This weakness could pose a serious threat to network security if left unaddressed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd