Tenda AC21
cpe:2.3:h:tenda:ac21:*:*:*:*:*:*:*, +1 more
- 16.03.08.16
A buffer overflow vulnerability has been identified in the Tenda AC21 router running version 16.03.08.16. The issue arises in the SetNetControlList file, specifically within the formSetQosBand function. The vulnerability can be exploited remotely by manipulating the argument list, leading to a buffer overflow condition. This flaw is critical as it could potentially allow for remote code execution.
Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or cause the device to crash.
The vulnerability can be reproduced by sending a crafted request to the /goform/SetNetControlList endpoint, manipulating the 'list' argument to trigger the buffer overflow.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.