Stack-Based Buffer Overflow in Tenda W15E Router
CVE-2024-4126

8.8HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
24 April 2024

Summary

A critical security vulnerability has been identified in Tenda's W15E router, specifically in the formSetSysTime function located in the /goform/SetSysTimeCfg file. This vulnerability allows for a stack-based buffer overflow triggered by improper manipulation of the manualTime argument. As a result, attackers may execute remote code, compromising the integrity and security of the device. The exploit for this vulnerability has been publicly disclosed, generating significant concerns regarding IoT device safety. Despite early warnings, Tenda has not responded to notifications regarding this issue, raising further alarm about the potential risks for users of affected products.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.