CVE-2023-38931
Last modified
CVE-2023-38931 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac10 Firmware | 15.03.06.23 |
| Tenda | Ac1206 Firmware | 15.03.06.23 |
| Tenda | Ac8 Firmware | 16.03.34.06 |
| Tenda | Ac6 Firmware | 15.03.06.23 |
| Tenda | Ac7 Firmware | 15.03.06.44 |
| Tenda | F1203 Firmware | 2.0.1.6 |
| Tenda | Ac5 Firmware | 15.03.06.28 |
| Tenda | Ac10 Firmware | 16.03.10.13 |
| Tenda | Fh1203 Firmware | 2.0.1.6 |
References
- https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/cloudv2_setaccount/README.mdExploit, Third Party Advisory
- https://github.com/FirmRec/IoT-Vulns/blob/main/tenda/cloudv2_setaccount/README.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-38931?
How severe is CVE-2023-38931?
How do I fix CVE-2023-38931?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-38925Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8…8.8
- CVE-2023-38926Netgear EX6200 v1.0.3.94 was discovered to contain a buffer …8.8
- CVE-2023-38928Netgear R7100LG 1.0.0.78 was discovered to contain a command…9.8
- CVE-2023-38929Tenda 4G300 v1.01.42 was discovered to contain a stack overf…9.8
- CVE-2023-3893A security issue was discovered in Kubernetes where a user t…8.8
- CVE-2023-38930Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03…9.8
- CVE-2023-38932Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH…9.8
- CVE-2023-38933Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2…9.8
- CVE-2023-38934Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(77…9.8
- CVE-2023-38935Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15…9.8
- CVE-2023-38936Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 …9.8
- CVE-2023-38937Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V1…9.8
Are you affected by CVE-2023-38931?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
