Stack-based buffer overflow in N300 and AC1350 - CVE-2023-49910
Published: April 12, 2024
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the web interface Radio Scheduling functionality within EAP115 ssid. A remote administrator can trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
AC1350
How to mitigate CVE-2023-49910
AC1350 - update to 5.1.6 20240313