CVE-2023-48194
CRITICALTenda AC8v4 Firmware V16.03.34.09 - Out-of-bounds Write via set_client_qos
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-48194. PoCs published by zt20xx.
AI-analyzed exploit summary The repository contains a functional PoC for CVE-2023-48194, a buffer overflow vulnerability in Tenda AC8v4 firmware V16.03.34.09. The exploit leverages a sscanf issue to overwrite the last digit of a buffer, leading to control over the gp register and a segmentation fault.
Description
Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained.
Exploits (1)
The repository contains a functional PoC for CVE-2023-48194, a buffer overflow vulnerability in Tenda AC8v4 firmware V16.03.34.09. The exploit leverages a sscanf issue to overwrite the last digit of a buffer, leading to control over the gp register and a segmentation fault.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H