CVE-2023-50991

Severity
7.5HIGH
EPSS
12.9%
top 5.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 5
Latest updateMay 8

Description

Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

โ–ถNVDtenda/i29_firmware1.0.0.2, 1.0.0.5+1

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-5f2c-q448-h62x: Buffer Overflow vulnerability in Tenda i29 versions 1โ†—2024-01-05
โ–ถ
CVEList
CVE-2023-50991: Buffer Overflow vulnerability in Tenda i29 versions 1โ†—2024-01-05
โ–ถ

๐Ÿ”Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Tenda pingSet pingIp parameter Buffer Overflow Attempt (CVE-2023-50991)โ†—2025-05-08
โ–ถ
CVE-2023-50991 (HIGH CVSS 7.5) | Buffer Overflow vulnerability in Te | cvebase.io