CVE-2023-44022
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Sep 27, 2023
CWE ID 119
Summary
CVE-2023-44022 is a newly discovered stack overflow vulnerability affecting the Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 firmware. This issue is located in the formSetSpeedWan function and can be exploited by sending maliciously crafted data to the speed_dir parameter. Successful exploitation may lead to a denial-of-service condition or potentially more serious consequences, such as remote code execution. Users of the affected device are urged to update their firmware as soon as a patch is made available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.