PT-2024-2599 · Tenda · Tenda Ac7

Wxhwxhwxh_Miemie

·

Published

2024-03-21

·

Updated

2025-01-22

·

CVE-2024-2891

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC7 version 15.03.06.44
Description A critical vulnerability was found in the function formQuickIndex of the file /goform/QuickIndex, which can be exploited remotely. The manipulation of the argument PPPOEPassword leads to a stack-based buffer overflow, potentially affecting the confidentiality, integrity, and availability of protected information. The exploit has been disclosed to the public and may be used.
Recommendations For Tenda AC7 version 15.03.06.44, update the firmware immediately to resolve the issue. If an update is unavailable, limit network access and monitor traffic as a temporary mitigation measure. Consider disabling the formQuickIndex function or restricting access to the /goform/QuickIndex file until a patch is available.

Exploit

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-02662
CVE-2024-2891

Affected Products

Tenda Ac7