Buffer Overflow Vulnerability in Tenda W15E Router
CVE-2024-4120

8.8HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
24 April 2024

Summary

A severe buffer overflow vulnerability exists in the Tenda W15E router, specifically within the modifyIpMacBind function found in the /goform/modifyIpMacBind file. This flaw is triggered by improper validation of inputs related to the IP mac binding process, specifically the parameters IPMacBindRuleId, IPMacBindRuleIp, IPMacBindRuleMac, and IPMacBindRuleRemark. A successful exploit could allow attackers to execute arbitrary code remotely, potentially compromising the device and gaining unauthorized access to the network. Despite early disclosures to Tenda, no response or remediation actions have been communicated. Organizations using affected versions are urged to apply security practices while awaiting an official patch.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.