Buffer Overflow Vulnerability in Tenda AC Routers
CVE-2018-18707
7.5HIGH
What is CVE-2018-18707?
A buffer overflow vulnerability exists in the web server component of certain Tenda AC routers. This flaw is triggered by specific post request parameters, particularly the 'ssid' parameter. When processed, the inadequate handling allows a direct copy into a local variable using strcpy, which can overwrite the function's return address. This vulnerability could be exploited to execute arbitrary code or disrupt the router's normal operation.