Buffer Overflow Vulnerability in Tenda AC Routers
CVE-2018-18707

7.5HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
29 October 2018

Summary

A buffer overflow vulnerability exists in the web server component of certain Tenda AC routers. This flaw is triggered by specific post request parameters, particularly the 'ssid' parameter. When processed, the inadequate handling allows a direct copy into a local variable using strcpy, which can overwrite the function's return address. This vulnerability could be exploited to execute arbitrary code or disrupt the router's normal operation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.