PT-2024-2597 · Tenda · Tenda Ac7

Wxhwxhwxh_Tutu

·

Published

2024-03-26

·

Updated

2025-01-22

·

CVE-2024-2895

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC7 version 15.03.06.44
Description A critical issue affects the formWifiWpsOOB function of the /goform/WifiWpsOOB file, caused by a stack-based buffer overflow. The manipulation of the index argument leads to this overflow. The attack can be initiated remotely, potentially impacting the confidentiality, integrity, and availability of protected information. An exploit for this issue has been publicly disclosed.
Recommendations For Tenda AC7 version 15.03.06.44, as a temporary workaround, consider disabling the formWifiWpsOOB function until a patch is available. Restrict access to the /goform/WifiWpsOOB file to minimize the risk of exploitation. Avoid using the index argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02660
CVE-2024-2895

Affected Products

Tenda Ac7