CVE-2023-37717
https://notcve.org/view.php?id=CVE-2023-37717
Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient. • https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/fromDhcpListClient/repot.md • CWE-787: Out-of-bounds Write •
CVE-2023-37711
https://notcve.org/view.php?id=CVE-2023-37711
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function. • https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/saveParentControlInfo • CWE-787: Out-of-bounds Write •
CVE-2023-37710
https://notcve.org/view.php?id=CVE-2023-37710
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function. • https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/fromSetWirelessRepeat • CWE-787: Out-of-bounds Write •
CVE-2023-37144
https://notcve.org/view.php?id=CVE-2023-37144
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac. • https://github.com/DaDong-G/Vulnerability_info/blob/main/ac10_command_injection/Readme.md • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-34568
https://notcve.org/view.php?id=CVE-2023-34568
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet. • https://hackmd.io/%400dayResearch/ryR8IzMH2 • CWE-787: Out-of-bounds Write •