Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-48194


Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.


Published

2024-07-09T18:15:08.790

Last Modified

2024-11-21T08:31:11.740

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tenda ac8v4_firmware 16.03.34.09 Yes
Hardware tenda ac8v4 - No

References