cbcvebase.
CVE-2023-38936
published 2023-08-07

CVE-2023-38936: Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

Affected

9 ranges
VendorProductVersion rangeFixed in
tendaac10_firmware
tendaac1206_firmware
tendaac5_firmware
tendaac6_firmware
tendaac7_firmware
tendaac9_firmware
tendaf1203_firmware
tendafh1203_firmware
tendafh1205_firmware