Stack-Based Buffer Overflow in Tenda AX1806 Device Name Functionality
CVE-2024-4238
8.8HIGH
What is CVE-2024-4238?
A critical security vulnerability exists in the Tenda AX1806 router, specifically within the formSetDeviceName function located in the /goform/SetOnlineDevName endpoint. This issue is characterized by a stack-based buffer overflow, which can be exploited remotely by an attacker. Manipulating the 'devName' argument within this function allows for malicious code execution, creating a significant risk for devices on affected networks. The vulnerability has been publicly disclosed but remains unaddressed, as the vendor has not responded to inquiries about remediation. It is crucial for users of the Tenda AX1806 to implement immediate security measures and monitor for any potential exploitation attempts.