CVE-2023-38931
CRITICALTenda AC10 AC1206 AC8 AC6 AC7 F1203 AC5 FH1203 Firmware - Stack Overflow via setaccount list Parameter
Title source: llmDescription
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/cloudv2_setaccount/README.md
Scores
CVSS v3
9.8
EPSS
0.0015
EPSS Percentile
35.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (9)
tenda/ac10_firmware
15.03.06.23
tenda/ac10_firmware
16.03.10.13
tenda/ac1206_firmware
15.03.06.23
tenda/ac5_firmware
15.03.06.28
tenda/ac6_firmware
15.03.06.23
tenda/ac7_firmware
15.03.06.44
tenda/ac8_firmware
16.03.34.06
tenda/f1203_firmware
2.0.1.6
tenda/fh1203_firmware
2.0.1.6
Published
Aug 07, 2023
Tracked Since
Feb 18, 2026