CVE-2023-38935
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
07/08/2023
Last modified:
10/08/2023
Description
Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac5_firmware:15.03.06.28:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac5:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac9_firmware:15.03.06.42_multi:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac9:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac8_firmware:16.03.34.06:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac8:4.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tenda:ac10_firmware:16.03.10.13:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac10:4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



