Ming Yuan

Researcher fromNISL@Tsinghua University
#3399of 53,632
75.9Total CVSS
Vulnerabilities · 9
High
6
Critical
3
PT-2018-14608
7.8
2018-10-28
Tenda · Tenda Ac10 · CVE-2018-18730
**Name of the Vulnerable Software and Affected Versions** Tenda AC7 version 15.03.06.44 CN Tenda AC9 version 15.03.05.19(6318) CN Tenda AC10 version 15.03.06.23 CN Tenda AC15 version 15.03.05.19 CN Tenda AC18 version 15.03.05.19(6318) CN **Description** A buffer overflow issue exists in the router's web server, specifically in the httpd. The problem arises when processing the `startIp` and `endIp` parameters for a post request. Each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function. **Recommendations** For Tenda AC7 version 15.03.06.44 CN, update the firmware to a version that addresses the buffer overflow vulnerability in the httpd web server. For Tenda AC9 version 15.03.05.19(6318) CN, update the firmware to a version that addresses the buffer overflow vulnerability in the httpd web server. For Tenda AC10 version 15.03.06.23 CN, update the firmware to a version that addresses the buffer overflow vulnerability in the httpd web server. For Tenda AC15 version 15.03.05.19 CN, update the firmware to a version that addresses the buffer overflow vulnerability in the httpd web server. For Tenda AC18 version 15.03.05.19(6318) CN, update the firmware to a version that addresses the buffer overflow vulnerability in the httpd web server. As a temporary workaround, consider restricting access to the httpd web server until a patch is available. Avoid using the `startIp` and `endIp` parameters in post requests to the vulnerable web server until the issue is resolved.