Tenda AC9
cpe:2.3:h:tenda:ac9:*:*:*:*:*:*:*, +1 more
- V15.03.05.14_multi
A stack overflow vulnerability has been identified in the Tenda AC9 router, version 1.0, running firmware V15.03.05.14_multi. The issue resides in the WifiWpsStart form, where the index parameter from POST requests is improperly handled. The vulnerability allows for remote arbitrary code execution.
Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected router.
To reproduce this vulnerability, send a POST request to the /goform/WifiWpsStart endpoint. Include an excessively long index parameter in the request. The lack of length validation in the firmware allows the long index to overflow the stack, potentially leading to arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.