Denial of Service and Code Execution Flaw in Tenda AC5 Router
CVE-2023-25212

9.8CRITICAL

Key Information:

Vendor
Tenda
Vendor
CVE Published:
7 April 2023

Summary

The Tenda AC5 Router is vulnerable to a stack overflow in the fromSetWirelessRepeat function, enabling attackers to trigger a Denial of Service condition or execute arbitrary code with specially crafted payloads. This vulnerability poses significant risks to users, compromising the integrity and availability of the affected systems.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.