Stack-Based Buffer Overflow Vulnerability in Tenda AX1806 Firmware
CVE-2024-40416

9.8CRITICAL

Key Information:

Vendor
Tenda
Vendor
CVE Published:
15 July 2024

Summary

A vulnerability found in the Tenda AX1806 firmware 1.0.0.1 compromises system integrity via a stack-based buffer overflow in the SetVirtualServerCfg function located within the /goform endpoint. This flaw arises from insufficient bounds checking on user-supplied input, allowing attackers to potentially manipulate memory and execute arbitrary code. Timely patching and security measures are crucial to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.