Buffer Overflow Vulnerability in Tenda AX1806 Product
CVE-2024-44565

9.8CRITICAL

Key Information:

Vendor
Tenda
Vendor
CVE Published:
26 August 2024

Summary

The Tenda AX1806 v1.0.0.1 is susceptible to a stack overflow vulnerability that occurs through improper handling of the serverName parameter in the form_fast_setting_internet_set function. This flaw can be exploited to induce unexpected behavior in the device, potentially allowing an attacker to execute arbitrary code or cause a denial of service. Proper input validation and boundaries should be implemented to mitigate this security risk and protect network integrity.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.