CVE-2023-34569
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Jun 8, 2023
Updated: Jan 6, 2025
CWE ID 787
Summary
CVE-2023-34569 refers to a stack overflow vulnerability identified in the US_AC10V4.0si_V16.03.10.13 firmware of Tenda AC10 v4 routers. This issue arises due to an improper handling of parameter lists in the /goform/SetNetControlList endpoint. An attacker can exploit this vulnerability by sending crafted input to trigger a stack overflow, potentially resulting in a denial-of-service condition or remote code execution with administrative privileges. Affected devices need to be updated with the latest firmware to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd