Tenda AC6
cpe:2.3:h:tenda:ac6:*:*:*:*:*:*:*, +1 more
- 15.03.05.16
A buffer overflow vulnerability has been identified in the Tenda AC6 router running firmware version 15.03.05.16. The issue arises in the formSetSpeedWan function, where the sprintf function is used to copy data from the speed_dir parameter to a buffer without proper boundary checks. This flaw allows for the possibility of overwriting adjacent memory, which could lead to a program crash and the exploitation of this vulnerability.
Exploitation of this vulnerability causes a buffer overflow, which can overwrite memory and potentially lead to arbitrary code execution or a denial-of-service condition by crashing the device.
The vulnerability can be reproduced by sending a POST request to the /goform/SetSpeedWan endpoint. The request must include a speed_dir parameter with a value that exceeds 8 bytes. This payload will trigger the buffer overflow by overwriting the memory area following the buffer that receives the data.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.