CVE-2023-38938
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-38938 refers to a stack overflow vulnerability affecting the Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5, and FH1202 V1.2.0.9 routers. Maliciously crafted input to the page parameter in the /L7Im endpoint can cause the routers to exhaust the available memory, resulting in a denial-of-service condition. Unauthorized users may exploit this flaw to cause service interruptions or potentially gain unauthorized access to the vulnerable systems. To mitigate the risk, users should update their routers to the latest available firmware as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd