CVE-2023-27063 is a critical buffer overflow vulnerability affecting Tenda W15e firmware (V15V1.0 V15.11.0.14(1521_3190_1058)). This flaw allows unauthenticated attackers to trigger a Denial of Service (DoS) by sending a specially crafted request to the formModifyDnsForward function, manipulating the DNSDomainName parameter. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction, leading to high impacts on confidentiality, integrity, and availability. Currently, there is no public exploit code available, it is not listed in CISA's KEV catalog, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.11.0.14CPE matchmatch criteria | cpe:2.3:o:tenda:w15e_firmware:15.11.0.14:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.