Tenda i22
cpe:2.3:h:tenda:i22:*:*:*:*:*:*:*, +1 more
- 1.0.0.3(4687)
A stack-based buffer overflow vulnerability has been identified in the Tenda i22 router, specifically in version 1.0.0.3(4687). The issue arises in the 'formWeixinAuthInfoGet' function within the '/goform/wxportalauth' file. The vulnerability can be exploited remotely by manipulating the 'type' parameter, leading to potential denial-of-service conditions or arbitrary code execution.
Exploitation of this vulnerability causes a stack-based buffer overflow, which can disrupt normal operation or allow for remote code execution.
To reproduce this vulnerability, send a POST request to '/goform/wxportalauth' with the 'type' parameter set to a string that is 8192 bytes long. This will overflow the stack-based buffer and trigger the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.