Tenda AC1206
cpe:2.3:h:tenda:ac1206:*:*:*:*:*:*:*, +1 more
- AC1206V1.0RTL_V15.03.06.23
A stack-based buffer overflow vulnerability has been identified in the Tenda AC1206 Wi-Fi 5 router, specifically in the firmware version 15.03.06.23. The vulnerability arises in the 'GetParentControlInfo' function within the '/goform/GetParentControlInfo' endpoint. The issue is caused by inadequate parameter restrictions and the absence of proper boundary checks, allowing unauthenticated remote attackers to manipulate the 'mac' argument and execute a denial-of-service attack.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the device to become unresponsive or unavailable.
The vulnerability can be reproduced by sending a crafted HTTP GET request to the '/goform/GetParentControlInfo' endpoint, with the 'mac' parameter containing a payload designed to overflow the buffer. This can be done using a Python script that automates the process of sending the malicious payload. The Tenda AC1206 router must be accessible on the local network for the attack to be successful.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.