PT-2024-2176 · Tenda · Tenda Ac18

Yhryhryhr

·

Published

2024-03-15

·

Updated

2025-01-14

·

CVE-2024-2486

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC18 version 15.03.05.05
Description A critical issue affects the formQuickIndex function of the /goform/QuickIndex file, allowing for a stack-based buffer overflow through the manipulation of the PPPOEPassword argument. This can be exploited remotely, potentially leading to privilege escalation by writing specially crafted data. The issue has been publicly disclosed.
Recommendations For Tenda AC18 version 15.03.05.05, as a temporary workaround, consider disabling the formQuickIndex function of the /goform/QuickIndex file until a patch is available. Restrict access to the /goform/QuickIndex endpoint to minimize the risk of exploitation. Avoid using the PPPOEPassword argument in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-02090
CVE-2024-2486

Affected Products

Tenda Ac18