PT-2019-9036 · Tenda · Tenda Ac9+2
Published
2019-04-25
·
Updated
2019-05-02
·
CVE-2018-14557
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC7 versions through V15.03.06.44 CN(AC7)
Tenda AC9 versions through V15.03.05.19(6318) CN(AC9)
Tenda AC10 versions through V15.03.06.23 CN(AC10)
Description
A buffer overflow issue exists in the router's web server (httpd) due to improper handling of page parameters for a post request. The
sprintf function directly writes the value to a local variable on the stack, overriding the return address of the function and causing a buffer overflow.Recommendations
For Tenda AC7 versions through V15.03.06.44 CN(AC7), update to a version later than V15.03.06.44 CN(AC7) to resolve the issue.
For Tenda AC9 versions through V15.03.05.19(6318) CN(AC9), update to a version later than V15.03.05.19(6318) CN(AC9) to resolve the issue.
For Tenda AC10 versions through V15.03.06.23 CN(AC10), update to a version later than V15.03.06.23 CN(AC10) to resolve the issue.
As a temporary workaround, consider restricting access to the router's web server (httpd) until a patch is available.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Ac10
Tenda Ac7
Tenda Ac9