Buffer Overflow Vulnerability in Tenda W15E Router
CVE-2024-4120
Summary
A severe buffer overflow vulnerability exists in the Tenda W15E router, specifically within the modifyIpMacBind function found in the /goform/modifyIpMacBind file. This flaw is triggered by improper validation of inputs related to the IP mac binding process, specifically the parameters IPMacBindRuleId, IPMacBindRuleIp, IPMacBindRuleMac, and IPMacBindRuleRemark. A successful exploit could allow attackers to execute arbitrary code remotely, potentially compromising the device and gaining unauthorized access to the network. Despite early disclosures to Tenda, no response or remediation actions have been communicated. Organizations using affected versions are urged to apply security practices while awaiting an official patch.
References
CVSS V3.1
Timeline
Vulnerability published