Tenda i22 Stack-Based Buffer Overflow Vulnerability in Weixin Auth Info Function

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the Tenda i22 router, specifically in version 1.0.0.3(4687). The issue arises in the 'formWeixinAuthInfoGet' function within the '/goform/wxportalauth' file. The vulnerability can be exploited remotely by manipulating the 'type' parameter, leading to potential denial-of-service conditions or arbitrary code execution.

Impact

Exploitation of this vulnerability causes a stack-based buffer overflow, which can disrupt normal operation or allow for remote code execution.

Reproduction

To reproduce this vulnerability, send a POST request to '/goform/wxportalauth' with the 'type' parameter set to a string that is 8192 bytes long. This will overflow the stack-based buffer and trigger the vulnerability.

Added: Aug 21, 2025, 1:21 PM
Updated: Aug 21, 2025, 2:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
9.1
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.