Stack Overflow Vulnerability in Tenda Routers G1 and G3
CVE-2021-45997
7.5HIGH
Summary
A stack overflow vulnerability exists in Tenda routers G1 and G3, specifically in the function formSetPortMapping. This security flaw allows an attacker to exploit various parameters related to port mapping, which can lead to a Denial of Service condition. By manipulating the portMappingServer, portMappingProtocol, portMappingWan, portMappingInternal, and portMappingExternal parameters, unauthorized users can disrupt the normal operation of the affected routers, compromising their availability.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved