Record summary

CVE-2024-10123 has a selected CVSS score of 8.7 (high).

Description

A vulnerability was found in Tenda AC8 16.03.34.06. It has been declared as critical. Affected by this vulnerability is the function compare_parentcontrol_time of the file /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This is not the same issue like CVE-2023-33671. The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 18, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List16.03.34.06affected

Default status: unknown

CVE List16.03.34.06affected

References

6
VDB-280915 | Tenda AC8 saveParentControlInfo compare_parentcontrol_time stack-based overflowvdb entryTechnical description
https://vuldb.com/?id.280915