Buffer Overflow Vulnerability in Tenda Router Web Server
CVE-2018-18727
7.5HIGH
What is CVE-2018-18727?
A buffer overflow issue has been identified in the web server (httpd) of specific Tenda router models. This vulnerability occurs when processing the 'deviceList' parameter in a post request, where the value is used unsafely in a strcpy operation. This can lead to stack memory corruption, which allows an attacker to manipulate the return address of the executed function, potentially enabling unauthorized actions on the affected devices.