PT-2019-9036 · Tenda · Tenda Ac9+2

Publicado

2019-04-25

·

Atualizado

2019-05-02

·

CVE-2018-14557

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC7 versions through V15.03.06.44 CN(AC7) Tenda AC9 versions through V15.03.05.19(6318) CN(AC9) Tenda AC10 versions through V15.03.06.23 CN(AC10)
Description A buffer overflow issue exists in the router's web server (httpd) due to improper handling of page parameters for a post request. The sprintf function directly writes the value to a local variable on the stack, overriding the return address of the function and causing a buffer overflow.
Recommendations For Tenda AC7 versions through V15.03.06.44 CN(AC7), update to a version later than V15.03.06.44 CN(AC7) to resolve the issue. For Tenda AC9 versions through V15.03.05.19(6318) CN(AC9), update to a version later than V15.03.05.19(6318) CN(AC9) to resolve the issue. For Tenda AC10 versions through V15.03.06.23 CN(AC10), update to a version later than V15.03.06.23 CN(AC10) to resolve the issue. As a temporary workaround, consider restricting access to the router's web server (httpd) until a patch is available.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14557

Produtos afetados

Tenda Ac10
Tenda Ac7
Tenda Ac9