ID

VAR-202311-2374


CVE

CVE-2023-49047


DESCRIPTION

Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.

Trust: 1.0

sources: NVD: CVE-2023-49047

AFFECTED PRODUCTS

vendor:tendamodel:ax1803scope:eqversion:1.0.0.1

Trust: 1.0

sources: NVD: CVE-2023-49047

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-49047
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2023-49047
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: NVD: CVE-2023-49047

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2023-49047

EXTERNAL IDS

db:NVDid:CVE-2023-49047

Trust: 1.0

sources: NVD: CVE-2023-49047

REFERENCES

url:https://github.com/anza2001/iot_vuln/blob/main/tenda/ax1803/formsetdevicename.md

Trust: 1.0

sources: NVD: CVE-2023-49047

SOURCES

db:NVDid:CVE-2023-49047

LAST UPDATE DATE

2024-08-14T13:19:38.211000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2023-49047date:2023-12-01T20:05:19.323

SOURCES RELEASE DATE

db:NVDid:CVE-2023-49047date:2023-11-27T17:15:08.470