Tenda W20E
cpe:2.3:h:tenda:w20e:*:*:*:*:*:*:*, +1 more
- V4.0br_V15.11.0.6
A buffer overflow vulnerability has been identified in the Tenda W20E router, specifically in version V4.0br_V15.11.0.6. The issue arises in the DHCP rule management feature, where attackers can send excessively long data through the 'addDhcpRules' parameter. The 'addDhcpRule' function processes this data without proper size validation, leading to potential buffer overflows in the 'dhcpsIndex', 'dhcpsIP', and 'dhcpsMac' variables.
Exploitation of this vulnerability can lead to arbitrary code execution or causing the device to become unresponsive.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.