← Vulnerability feed

Vulnerability record · CVE-2023-50991 · published 5 January 2024

CVE-2023-50991: Tenda i29 firmware classic buffer overflow vulnerability

Tenda · I29 Firmware

Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.

7.5 CVSS 3.1 High EPSS 8.8% · top 5.0% CWE-120 · Classic buffer overflow
7.5CVSS 3.1 base score
8.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp parameter in the pingSet function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-50991 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-50988Tenda i29 firmware out-of-bounds write vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.EPSS 0.77%9.8CVE-2023-50989Tenda i29 firmware command injection vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.EPSS 2.0%9.8CVE-2023-50990Tenda i29 firmware out-of-bounds write vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.EPSS 0.77%9.8CVE-2023-50992Tenda i29 firmware out-of-bounds write vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.EPSS 0.77%9.8CVE-2023-50983Tenda i29 firmware command injection vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.EPSS 2.0%9.8CVE-2023-50984Tenda i29 firmware out-of-bounds write vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.EPSS 0.76%9.8CVE-2023-50985Tenda i29 firmware out-of-bounds write vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.EPSS 0.76%9.8CVE-2023-50986Tenda i29 firmware out-of-bounds write vulnerabilityTenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2023-50991), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.