CVE-2023-37711
https://notcve.org/view.php?id=CVE-2023-37711
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function. • https://github.com/FirmRec/IoT-Vulns/tree/main/tenda/saveParentControlInfo • CWE-787: Out-of-bounds Write •
CVE-2023-37144
https://notcve.org/view.php?id=CVE-2023-37144
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac. • https://github.com/DaDong-G/Vulnerability_info/blob/main/ac10_command_injection/Readme.md • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2023-34571
https://notcve.org/view.php?id=CVE-2023-34571
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet. • https://hackmd.io/%400dayResearch/S1GcUxzSn • CWE-787: Out-of-bounds Write •
CVE-2023-34570
https://notcve.org/view.php?id=CVE-2023-34570
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName. • https://hackmd.io/%400dayResearch/S1eI91_l2 • CWE-787: Out-of-bounds Write •
CVE-2023-34567
https://notcve.org/view.php?id=CVE-2023-34567
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg. • https://hackmd.io/%400dayResearch/H1xUqzfHh • CWE-787: Out-of-bounds Write •