Stack-Based Buffer Overflow in Tenda AX1806 Device Name Functionality
CVE-2024-4238

8.8HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
26 April 2024

Summary

A critical security vulnerability exists in the Tenda AX1806 router, specifically within the formSetDeviceName function located in the /goform/SetOnlineDevName endpoint. This issue is characterized by a stack-based buffer overflow, which can be exploited remotely by an attacker. Manipulating the 'devName' argument within this function allows for malicious code execution, creating a significant risk for devices on affected networks. The vulnerability has been publicly disclosed but remains unaddressed, as the vendor has not responded to inquiries about remediation. It is crucial for users of the Tenda AX1806 to implement immediate security measures and monitor for any potential exploitation attempts.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.