Tenda W6 httpd setcfm formSetCfm stack-based overflow
CVE-2024-0994
Key Information:
Badges
Summary
A vulnerability exists in Tenda W6 firmware version 1.0.0.9(4122), specifically within the function formSetCfm located in the /goform/setcfm file of the httpd component. This flaw allows attackers to execute a stack-based buffer overflow through manipulation of the argument funcpara1. The vulnerability can be exploited remotely, enabling potential attackers to compromise the device without physical access. The exploit has been publicly disclosed, raising concerns about the security of affected devices. Despite attempts to notify the vendor, there has been no response regarding this critical security issue.
Affected Version(s)
W6 1.0.0.9(4122)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved