Tenda AX1806 V1.0.0.1 contains a heap overflow...
Critical severity
Unreviewed
Published
Nov 14, 2023
to the GitHub Advisory Database
•
Updated Sep 5, 2024
Description
Published by the National Vulnerability Database
Nov 7, 2023
Published to the GitHub Advisory Database
Nov 14, 2023
Last updated
Sep 5, 2024
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
References