Tenda AC10U
cpe:2.3:h:tenda:ac10u:*:*:*:*:*:*:*, +1 more
- 15.03.06.48
- 15.03.06.49
A buffer overflow vulnerability has been identified in the Tenda AC10U router, specifically in firmware versions 15.03.06.48 and 15.03.06.49. The issue arises in the 'formSetPPTPUserList' function within the '/goform/setPptpUserList' file, which is part of the HTTP POST Request Handler component. The vulnerability allows for remote exploitation by manipulating the 'list' parameter, leading to a buffer overflow condition.
Exploitation of this vulnerability causes a buffer overflow, which can potentially be used to execute arbitrary code or cause a denial-of-service condition on the device.
To reproduce this vulnerability, send an HTTP POST request to the '/goform/setPptpUserList' endpoint with a crafted 'list' parameter that exceeds the buffer size. The 'formSetPPTPUserList' function will process the request, and the overflow will occur when the parameter is copied without proper size validation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.