Tenda AC20 Buffer Overflow Vulnerability in Parent Control Function
Vulnerability
A buffer overflow vulnerability has been identified in the Tenda AC20 router, affecting firmware versions through 16.03.08.12. The issue arises in the '/goform/saveParentControlInfo' endpoint, where the 'time' parameter is manipulated, leading to a buffer overflow. This vulnerability can be exploited remotely, and public knowledge of the exploit exists.
Impact
Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or a denial-of-service condition on the device.
Reproduction
To reproduce this vulnerability, send a POST request to '/goform/saveParentControlInfo' with a crafted 'time' parameter that exceeds the expected length, bypassing any input validation. The 'deviceName' field can also be included in the request.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
