CVE-2023-50990

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 20, 2023
Updated: Dec 22, 2023
CWE ID 787

Summary

CVE-2023-50990 is a newly discovered vulnerability affecting Tenda i29 routers running firmware V1.0.0.5. The issue stems from a buffer overflow flaw in the sysScheduleRebootSet function, which can be triggered via the rebootTime parameter. An attacker can exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition, potentially leading to significant network disruptions. Router users are advised to update their firmware as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share