Buffer Overflow Vulnerability in Tenda Home Routers
CVE-2018-18731
7.5HIGH
Summary
A buffer overflow vulnerability has been identified in the web server of various Tenda routers, including AC7, AC9, AC10, AC15, and AC18. This issue arises when handling the 'deviceMac' parameter during a POST request. The improper use of this parameter leads to a sprintf function call that overwrites a local variable on the stack, compromising the return address of the function. This vulnerability could potentially allow unauthorized users to execute arbitrary code, putting device integrity and connected networks at risk.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved