Stack Overflow Vulnerability in Tenda Routers G1 and G3
CVE-2021-45992
7.5HIGH
Summary
A stack overflow vulnerability has been identified in Tenda routers G1 and G3, versions v15.11.0.17(9502)_CN. This security flaw exists in the function formSetQvlanList which can be exploited by attackers through the qvlanName parameter. Successful exploitation of this vulnerability may lead to a Denial of Service (DoS) condition, disrupting network availability for users reliant on these devices. It is essential for Tenda router users to apply available updates and implement security best practices to mitigate potential risks.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved