Tenda F451 Buffer Overflow Vulnerability in Web Exception Type Manager Filter
Vulnerability
A buffer overflow vulnerability has been identified in the Tenda F451 router, specifically in the firmware version 1.0.0.7_cn_svn7958. The issue arises in the 'fromwebExcptypemanFilter' function within the 'httpd' component. The vulnerability is triggered by manipulating the 'page' parameter, which is passed to the 'sprintf' function without proper length validation, leading to a stack-based buffer overflow. This vulnerability can be exploited remotely, potentially causing a denial-of-service condition or allowing for remote code execution.
Impact
Exploitation of this vulnerability leads to a buffer overflow, with the potential for remote code execution or causing a denial-of-service condition on the device.
Reproduction
The vulnerability can be reproduced by sending a POST request to the '/goform/webExcptypemanFilter' endpoint with a 'page' parameter that contains a payload designed to overflow the buffer. This can be done using a script or tool that automates the process of sending the request with the malicious payload.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
