CVE-2023-47455: Tenda AX1806 Firmware
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size.
Affected products
- Tenda AX1806 Firmware: version 1.0.0.1 only
Published 2023-11-07. Last modified 2026-06-17.