CVE-2023-47455
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
07/11/2023
Last modified:
28/10/2024
Description
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tenda:ax1806_firmware:1.0.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ax1806:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



