CVE-2023-50991
published 2024-01-05CVE-2023-50991: Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
8.84%
94.6th percentile
Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | i29_firmware | — | — |
| tenda | i29_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Tenda pingSet pingIp parameter Buffer Overflow Attempt (CVE-2023-50991)
suricata·2025-05-08·CVSS 7.5
CVE-2023-50991 [HIGH] ET WEB_SPECIFIC_APPS Tenda pingSet pingIp parameter Buffer Overflow Attempt (CVE-2023-50991)
ET WEB_SPECIFIC_APPS Tenda pingSet pingIp parameter Buffer Overflow Attempt (CVE-2023-50991)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Tenda pingSet pingIp parameter Buffer Overflow Attempt (CVE-2023-50991)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:15; content:"/goform/modules"; http.request_body; content:"pingSet"; fast_pattern; content:"pingIp"; pcre:"/^\x22\x3a[^\x2c\x7d$]{100,}(?:\x2c|\x7d|$)/R"; reference:cve,2023-50991; reference:url,github.com/02Tn/vul/issues; classtype:web-application-attack; sid:2062207; rev:2; metadata:affected_product Tenda, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_05_08, cve CVE_2023_50991, deployment Perimeter, deployment Internal, performance_impact Low, confidence Hi
No public exploits indexed.
No writeups or analysis indexed.
2024-01-05
Published