ID

VAR-202407-0512


CVE

CVE-2023-48194


TITLE

Shenzhen Tenda Technology Co.,Ltd.  of  ac8v4  Firmware vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2023-026231

DESCRIPTION

Vulnerability in Tenda AC8v4 .V16.03.34.09 due to sscanf and the last digit of s8 being overwritten with \x0. After executing set_client_qos, control over the gp register can be obtained. Shenzhen Tenda Technology Co.,Ltd. of ac8v4 There are unspecified vulnerabilities in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda AC8 is a dual-gigabit wireless router designed for homes with fiber optic connections up to 1000 Mbps. It supports IPv6 and features intelligent network management

Trust: 2.16

sources: NVD: CVE-2023-48194 // JVNDB: JVNDB-2023-026231 // CNVD: CNVD-2025-24489

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-24489

AFFECTED PRODUCTS

vendor:tendamodel:ac8scope:eqversion:16.03.34.09

Trust: 1.6

vendor:tendamodel:ac8v4scope: - version: -

Trust: 0.8

vendor:tendamodel:ac8v4scope:eqversion: -

Trust: 0.8

vendor:tendamodel:ac8v4scope:eqversion:ac8v4 firmware 16.03.34.09

Trust: 0.8

vendor:tendamodel:ac8scope:eqversion:4

Trust: 0.6

sources: CNVD: CNVD-2025-24489 // JVNDB: JVNDB-2023-026231 // NVD: CVE-2023-48194

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-48194
value: CRITICAL

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2023-48194
value: MEDIUM

Trust: 1.0

NVD: CVE-2023-48194
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2025-24489
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-24489
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2023-48194
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2023-48194
baseSeverity: MEDIUM
baseScore: 6.3
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 2.8
impactScore: 3.4
version: 3.1

Trust: 1.0

NVD: CVE-2023-48194
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-24489 // JVNDB: JVNDB-2023-026231 // NVD: CVE-2023-48194 // NVD: CVE-2023-48194

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-787

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-026231 // NVD: CVE-2023-48194

EXTERNAL IDS

db:NVDid:CVE-2023-48194

Trust: 3.2

db:JVNDBid:JVNDB-2023-026231

Trust: 0.8

db:CNVDid:CNVD-2025-24489

Trust: 0.6

sources: CNVD: CNVD-2025-24489 // JVNDB: JVNDB-2023-026231 // NVD: CVE-2023-48194

REFERENCES

url:http://tenda.com

Trust: 1.8

url:https://github.com/zt20xx/cve-2023-48194

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-48194

Trust: 1.4

url:https://www.tenda.com.cn/download/detail-3683.html

Trust: 1.0

sources: CNVD: CNVD-2025-24489 // JVNDB: JVNDB-2023-026231 // NVD: CVE-2023-48194

SOURCES

db:CNVDid:CNVD-2025-24489
db:JVNDBid:JVNDB-2023-026231
db:NVDid:CVE-2023-48194

LAST UPDATE DATE

2025-12-18T00:31:44.840000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-24489date:2025-10-22T00:00:00
db:JVNDBid:JVNDB-2023-026231date:2024-07-16T03:02:00
db:NVDid:CVE-2023-48194date:2025-12-08T13:14:17.633

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-24489date:2025-10-22T00:00:00
db:JVNDBid:JVNDB-2023-026231date:2024-07-16T00:00:00
db:NVDid:CVE-2023-48194date:2024-07-09T18:15:08.790