Tenda AC8
cpe:2.3:h:tenda:ac8:*:*:*:*:*:*:*, +1 more
- V16.03.34.06
A stack buffer overflow vulnerability has been identified in the Tenda AC8 router, specifically in version V16.03.34.06. The issue arises in the 'fromSetRouteStatic' function within the 'tdhttpd' process, located in the '/bin' directory. The vulnerability can be exploited by sending a crafted request to the 'goform/SetStaticRouteCfg' endpoint, which triggers the buffer overflow.
Exploitation of this vulnerability leads to a stack buffer overflow, which can potentially allow for arbitrary code execution or causing a denial-of-service condition by crashing the device.
To reproduce this vulnerability, send a request to the 'goform/SetStaticRouteCfg' endpoint with a crafted payload that exceeds the buffer size expected by the 'fromSetRouteStatic' function. This can be done using a tool that allows for the manipulation of HTTP requests, such as Burp Suite or a custom script.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.