Stack-Based Buffer Overflow in Tenda W15E Router
CVE-2024-4126
8.8HIGH
What is CVE-2024-4126?
A critical security vulnerability has been identified in Tenda's W15E router, specifically in the formSetSysTime function located in the /goform/SetSysTimeCfg file. This vulnerability allows for a stack-based buffer overflow triggered by improper manipulation of the manualTime argument. As a result, attackers may execute remote code, compromising the integrity and security of the device. The exploit for this vulnerability has been publicly disclosed, generating significant concerns regarding IoT device safety. Despite early warnings, Tenda has not responded to notifications regarding this issue, raising further alarm about the potential risks for users of affected products.