Tenda W30E
cpe:2.3:h:tenda:w30e:*:*:*:*:*:*:*, +1 more
- <= V16.01.0.19(5037)
A stack overflow vulnerability has been identified in the Tenda W30E router, specifically in version 16.01.0.19 (5037). The issue arises in the werlessAdvancedSet function, where the countryCode parameter is processed without proper length validation. This flaw enables remote attackers to craft HTTP POST requests that overflow a stack-based buffer, leading to a denial-of-service condition or potentially allowing remote code execution.
Exploitation of this vulnerability causes a denial-of-service condition, with the possibility of remote code execution.
The vulnerability can be reproduced by sending an HTTP POST request to the /goform/setAdvancedSetList endpoint with a crafted countryCode parameter that is excessively long, such as 1000 characters. This can be done using a script that automates the request, such as one written in Python using the requests library.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.