CVE-2023-38931
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
07/08/2023
Last modified:
10/08/2023
Description
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tenda:ac10_firmware:15.03.06.23:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac10:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac8_firmware:16.03.34.06:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac8:4.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:f1203_firmware:2.0.1.6:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:f1203:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac5_firmware:15.03.06.28:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac5:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac10_firmware:16.03.10.13:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



