CVE-2023-25231 β€” Out-of-bounds Write in W30e Firmware

Severity
9.8CRITICALNVD
EPSS
0.4%
top 37.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27

Description

Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

β–ΆNVDtenda/w30e_firmwarev1.0.1.25\(633\)

πŸ”΄Vulnerability Details

2
CVEList
CVE-2023-25231: Tenda Router W30E V1β†—2023-02-27
β–Ά
GHSA
GHSA-2657-gffw-m33g: Tenda Router W30E V1β†—2023-02-27
β–Ά
CVE-2023-25231 β€” Out-of-bounds Write in Tenda | cvebase