CVE-2023-38936

Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac10_firmware:15.03.06.23:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac10:1.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tenda:f1203_firmware:2.0.1.6:*:*:*:*:*:*:*
cpe:2.3:h:tenda:f1203:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:tenda:ac5_firmware:15.03.06.28:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac5:1.0:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tenda:fh1203_firmware:2.0.1.6:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1203:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:tenda:fh1205_firmware:2.0.0.7\(775\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1205:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:tenda:ac9_firmware:15.03.06.42_multi:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac9:3.0:*:*:*:*:*:*:*

History

10 Aug 2023, 18:20

Type Values Removed Values Added
First Time Tenda ac5
Tenda
Tenda ac9
Tenda f1203
Tenda ac1206
Tenda fh1205 Firmware
Tenda fh1205
Tenda fh1203
Tenda ac10 Firmware
Tenda ac1206 Firmware
Tenda ac7
Tenda ac10
Tenda f1203 Firmware
Tenda ac5 Firmware
Tenda fh1203 Firmware
Tenda ac6
Tenda ac9 Firmware
Tenda ac6 Firmware
Tenda ac7 Firmware
CPE cpe:2.3:o:tenda:ac10_firmware:15.03.06.23:*:*:*:*:*:*:*
cpe:2.3:o:tenda:f1203_firmware:2.0.1.6:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1203:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac9_firmware:15.03.06.42_multi:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac10:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1205_firmware:2.0.0.7\(775\):*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac5_firmware:15.03.06.28:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1203_firmware:2.0.1.6:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac9:3.0:*:*:*:*:*:*:*
cpe:2.3:h:tenda:f1203:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac6_firmware:15.03.06.23:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac5:1.0:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1205:-:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetSpeedWan/README.md - (MISC) https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/formSetSpeedWan/README.md - Exploit, Vendor Advisory
CWE CWE-787

07 Aug 2023, 19:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-07 19:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-38936

Mitre link : CVE-2023-38936

CVE.ORG link : CVE-2023-38936


JSON object : View

Products Affected

tenda

  • ac7_firmware
  • ac6
  • ac9_firmware
  • fh1205
  • f1203_firmware
  • f1203
  • ac10
  • ac1206_firmware
  • fh1203
  • ac1206
  • fh1205_firmware
  • ac9
  • ac5
  • ac5_firmware
  • fh1203_firmware
  • ac7
  • ac10_firmware
  • ac6_firmware
CWE
CWE-787

Out-of-bounds Write