CVE-2023-48194

CRITICAL

Tenda AC8v4 Firmware V16.03.34.09 - Out-of-bounds Write via set_client_qos

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-48194. PoCs published by zt20xx.

AI-analyzed exploit summary The repository contains a functional PoC for CVE-2023-48194, a buffer overflow vulnerability in Tenda AC8v4 firmware V16.03.34.09. The exploit leverages a sscanf issue to overwrite the last digit of a buffer, leading to control over the gp register and a segmentation fault.

Description

Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.

Exploits (1)

nomisec WORKING POC
by zt20xx · poc
https://github.com/zt20xx/CVE-2023-48194

The repository contains a functional PoC for CVE-2023-48194, a buffer overflow vulnerability in Tenda AC8v4 firmware V16.03.34.09. The exploit leverages a sscanf issue to overwrite the last digit of a buffer, leading to control over the gp register and a segmentation fault.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Tenda AC8v4 V16.03.34.09
No auth needed
Prerequisites: Network access to the vulnerable device · Device running affected firmware version
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0082
EPSS Percentile 52.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (1)
tenda/ac8_firmware 16.03.34.09
Published Jul 09, 2024
Tracked Since Feb 18, 2026