Stack-based buffer overflow vulnerability in Tenda AC500 2.0.1.9(1307)
CVE-2024-3905
8.8HIGH
What is CVE-2024-3905?
A vulnerability exists in the Tenda AC500, specifically in the R7WebsSecurityHandler function within the /goform/execCommand file. This security flaw can be exploited by manipulating the 'password' argument, leading to a stack-based buffer overflow. Attackers can launch remote attacks, potentially compromising the affected device. Although the vulnerability has been disclosed publicly, there has been no response from Tenda Technologies following initial contact regarding this issue. For a detailed technical description, refer to VDB-261141.
Affected Version(s)
AC500 2.0.1.9(1307)