CVE-2023-41554
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Aug 30, 2023
Updated: Aug 31, 2023
CWE ID 787
Summary
CVE-2023-41554 is a stack overflow vulnerability affecting the Tenda AC9 V3.0 V15.03.06.42_multi firmware. The issue is located in the wpapsk_crypto parameter of the /goform/WifiExtraSet URL. An attacker could exploit this vulnerability by sending specially crafted data to the affected device, resulting in a stack overflow condition and potential crashes or remote code execution. This vulnerability poses a significant risk to users of the Tenda AC9 router, and it is recommended that they update their firmware to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd