Stack-Based Buffer Overflow in Tenda W15E Router
CVE-2024-4126
8.8HIGH
Summary
A critical security vulnerability has been identified in Tenda's W15E router, specifically in the formSetSysTime function located in the /goform/SetSysTimeCfg file. This vulnerability allows for a stack-based buffer overflow triggered by improper manipulation of the manualTime argument. As a result, attackers may execute remote code, compromising the integrity and security of the device. The exploit for this vulnerability has been publicly disclosed, generating significant concerns regarding IoT device safety. Despite early warnings, Tenda has not responded to notifications regarding this issue, raising further alarm about the potential risks for users of affected products.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published