Heap Overflow Vulnerability in Tenda AX1806 Router
CVE-2023-47455
9.1CRITICAL
What is CVE-2023-47455?
The Tenda AX1806 V1.0.0.1 router has a heap overflow vulnerability within the setSchedWifi function. This vulnerability arises because the function retrieves values for schedStartTime and schedEndTime directly from HTTP request parameters without proper size validation. This oversight can potentially allow an attacker to manipulate memory, leading to unauthorized access or denial of service. Users of the affected device should take immediate action to mitigate risks associated with this vulnerability.