Tenda W20E
cpe:2.3:h:tenda:w20e:*:*:*:*:*:*:*, +1 more
- V4.0br_V15.11.0.6
A buffer overflow vulnerability has been identified in the Tenda W20E router, specifically in version V4.0br_V15.11.0.6. The issue arises in the goform/formDelWewifiPic component, where attackers can manipulate the picName parameter. This parameter is processed using sprintf without proper size validation, creating the potential for a buffer overflow exploit.
Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing the device to crash.
To reproduce this vulnerability, send a POST request to the /goform/formDelWewifiPic endpoint. Include a picName parameter with a value that exceeds the buffer size limit. The request should be made with a Content-Type of application/x-www-form-urlencoded.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.