Tenda A15 Buffer Overflow Vulnerability in HTTP POST Request Handler

Vulnerability

A critical buffer overflow vulnerability has been identified in the Tenda A15 router, specifically in the firmware versions 15.13.07.09 and 15.13.07.13. The vulnerability resides within the HTTP POST request handler, in a file called '/goform/multimodalAdd'. This issue allows for remote exploitation, where an attacker can manipulate input to cause a buffer overflow, potentially leading to arbitrary code execution or causing the device to crash.

Impact

Exploitation of this vulnerability causes a denial-of-service condition, where the device crashes and becomes unresponsive.

Reproduction

The vulnerability can be reproduced by sending an HTTP POST request to the '/goform/multimodalAdd' endpoint. The request must include a 'Content-Length' header that specifies a length greater than what the buffer can handle. This can be done using a script that automates the process, such as one written in Python using the 'requests' library.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.