CVE-2023-33670

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 2, 2023
Updated: Jan 8, 2025
CWE ID 787

Summary

CVE-2023-33670 is a newly identified vulnerability affecting the Tenda AC8V firmware version 4.0-V16.03.34.06. This issue involves a stack overflow, which can be triggered by supplying maliciously crafted input to the time parameter in the sub_4a79ec function. Successful exploitation of this vulnerability could result in the crashing of the device or even allow an attacker to execute arbitrary code with the privileges of the affected component. Users of the Tenda AC8V router are strongly advised to update their firmware to a secure and patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share