Stack-based buffer overflow vulnerability in Tenda AC500 2.0.1.9(1307)
CVE-2024-3905
Key Information:
Badges
Summary
A vulnerability exists in the Tenda AC500, specifically in the R7WebsSecurityHandler function within the /goform/execCommand file. This security flaw can be exploited by manipulating the 'password' argument, leading to a stack-based buffer overflow. Attackers can launch remote attacks, potentially compromising the affected device. Although the vulnerability has been disclosed publicly, there has been no response from Tenda Technologies following initial contact regarding this issue. For a detailed technical description, refer to VDB-261141.
Affected Version(s)
AC500 2.0.1.9(1307)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved