Buffer Overflow Vulnerability in Tenda AC500 Wireless Router
CVE-2023-25235
7.5HIGH
Summary
A buffer overflow vulnerability exists in the Tenda AC500 router's firmware, specifically in the formOneSsidCfgSet function. This issue arises when the ssid parameter is inadequately validated, allowing an attacker to potentially execute arbitrary code by sending specially crafted requests. It highlights the importance of proper input validation to prevent such vulnerabilities.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved