Stack-Based Buffer Overflow in Tenda AC15 Parental Control Settings
CVE-2024-2852
What is CVE-2024-2852?
A significant vulnerability exists in Tenda AC15 routers, specifically in the parental control functionality. The issue stems from the saveParentControlInfo function located in /goform/saveParentControlInfo, which is susceptible to a stack-based buffer overflow. By manipulating the 'urls' parameter, attackers can execute arbitrary code remotely, leading to potential system compromise. This vulnerability has been publicly disclosed and poses a considerable risk to users. Tenda has yet to respond to vulnerability notifications, leaving devices exposed. Users are strongly advised to monitor for updates and apply any available security patches promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AC15 15.03.20_multi
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved