Buffer Overflow Vulnerability in Tenda Router Web Server
CVE-2018-18706
7.5HIGH
Summary
A buffer overflow vulnerability exists in the web server of Tenda routers, specifically in the handling of the 'page' parameter within the 'fromDhcpListClient' function. This flaw allows arbitrary data to overwrite memory locations, potentially compromising the return address of the function. Exploiting this vulnerability could enable an attacker to execute arbitrary code, posing serious security risks to the affected devices. Users of Tenda AC7, AC9, AC10, AC15, and AC18 routers are advised to apply available patches to mitigate the threat.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved