Tenda AC9
cpe:2.3:h:tenda:ac9:*:*:*:*:*:*:*, +1 more
- V15.03.05.14_multi
A stack overflow vulnerability has been identified in the Tenda AC9 router, specifically in version 1.0 with firmware V15.03.05.14_multi. The issue arises in the wanSpeed parameter of the /goform/AdvSetMacMtuWan endpoint, where improper handling of data can lead to a buffer overflow. This vulnerability allows for remote arbitrary code execution on the affected device.
Exploitation of this vulnerability allows for remote arbitrary code execution on the affected router.
To reproduce this vulnerability, send a POST request to the /goform/AdvSetMacMtuWan endpoint. Include a crafted wanSpeed parameter with a payload designed to overflow the stack. The overflow can be exploited to execute arbitrary code remotely on the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.