Tenda AC9
cpe:2.3:h:tenda:ac9:*:*:*:*:*:*:*, +1 more
- 15.03.02.13
A critical buffer overflow vulnerability has been identified in the Tenda AC9 router, specifically in the version 15.03.02.13. The issue arises in the POST request handler function 'fromadvsetlanip', located in the file '/goform/AdvSetLanip'. The vulnerability is triggered by manipulating the 'lanMask' parameter, which is received from a POST request and improperly handled, leading to a buffer overflow. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.
Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or a denial-of-service condition on the device.
To reproduce this vulnerability, send a POST request to the '/goform/AdvSetLanip' endpoint with a crafted 'lanMask' parameter that exceeds the expected buffer size. The 'fromadvsetlanip' function will process the request, leading to a buffer overflow condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.