CVE-2023-24332Stack-based Buffer Overflow in AC6 Firmware

Severity
8.1HIGHNVD
EPSS
0.1%
top 69.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 21

Description

A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages1 packages

NVDtenda/ac6_firmware03.03.02.01_cn_tdc01

🔴Vulnerability Details

2
GHSA
GHSA-vmh4-jjxc-hgm4: A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V52024-02-21
CVEList
CVE-2023-24332: A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V52024-02-21
CVE-2023-24332 — Stack-based Buffer Overflow in Tenda | cvebase