Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.
References
Link | Resource |
---|---|
http://tenda.com | Not Applicable |
https://github.com/zt20xx/CVE-2023-48194 | Exploit |
https://www.tenda.com.cn/download/detail-3683.html | |
http://tenda.com | Not Applicable |
https://github.com/zt20xx/CVE-2023-48194 | Exploit |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://tenda.com - Not Applicable | |
References | () https://github.com/zt20xx/CVE-2023-48194 - Exploit |
24 Oct 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Jul 2024, 17:13
Type | Values Removed | Values Added |
---|---|---|
References | () http://tenda.com - Not Applicable | |
References | () https://github.com/zt20xx/CVE-2023-48194 - Exploit | |
First Time |
Tenda ac8v4
Tenda ac8v4 Firmware Tenda |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:h:tenda:ac8v4:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac8v4_firmware:16.03.34.09:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
11 Jul 2024, 15:05
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
CWE | CWE-787 |
09 Jul 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 18:15
Updated : 2024-11-21 08:31
NVD link : CVE-2023-48194
Mitre link : CVE-2023-48194
CVE.ORG link : CVE-2023-48194
JSON object : View
Products Affected
tenda
- ac8v4_firmware
- ac8v4
CWE