Tenda i3 Stack-Based Buffer Overflow Vulnerability in the formexeCommand Function
Vulnerability
A stack-based buffer overflow vulnerability has been identified in the Tenda i3 router, specifically in version 1.0.0.6(2204). The issue arises in the formexeCommand function within the /goform/exeCommand file. This vulnerability can be exploited remotely by manipulating the cmdinput parameter, leading to potential unauthorized memory access and code execution.
Impact
Exploitation of this vulnerability causes a stack-based buffer overflow, which can lead to arbitrary code execution on the device.
Reproduction
The vulnerability can be reproduced by sending a crafted HTTP POST request to the /goform/exeCommand endpoint. The request must include an excessively long cmdinput parameter, which will overflow the buffer and potentially allow for code execution.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
