PT-2024-16210 · Tenda · Tenda Rx9 Pro

Guoxb

·

Published

2024-10-24

·

Updated

2024-11-01

·

CVE-2024-10351

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda RX9 Pro version 22.03.02.20
Description A critical issue affects the function sub 424CE0 of the file /goform/setMacFilterCfg in the component POST Request Handler. The manipulation of the deviceList argument leads to a stack-based buffer overflow. This issue can be exploited remotely.
Recommendations For Tenda RX9 Pro version 22.03.02.20, as a temporary workaround, consider restricting access to the /goform/setMacFilterCfg endpoint until a patch is available. Avoid manipulating the deviceList argument in the affected POST Request Handler to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-10351

Affected Products

Tenda Rx9 Pro