CVE detail
CVE-2023-40839 — CVE-2023-40839
Published 2023-08-30 · Modified 2026-06-17 · Vendor tenda · Product ac6_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0095
EPSS probability
exploitation probability, 30d
58.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADF3C' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADF3C" function to execute commands.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References