Remote Code Execution Vulnerability in Tenda AC5 Router
CVE-2023-31587
9.8CRITICAL
Summary
The Tenda AC5 router, specifically version V15.03.06.28, contains a vulnerability that allows an attacker to execute arbitrary code remotely via the Mac parameter at the ip/goform/WriteFacMac endpoint. This flaw could potentially allow unauthorized access to the device, leading to a compromise of network integrity and user data. Users are advised to apply necessary security measures and updates to safeguard against potential exploitation.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved