In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.
2023-08-25T16:15:08.510
2024-11-21T08:20:08.363
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tenda | ac23_firmware | 16.03.07.45_cn | Yes |
Hardware | tenda | ac23 | - | No |