PT-2024-35142 · Tenda · Tenda Ac6V2
Ba1100N
·
Published
2024-12-04
·
Updated
2025-05-28
·
CVE-2024-52272
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda AC6V2 versions through 15.03.06.50
Description
The issue is a stack-based buffer overflow vulnerability in the fromAdvSetLanip module, specifically with the
lanMask argument, allowing buffer overflows. This problem affects Tenda AC6V2 devices, potentially allowing attackers to overflow buffers.Recommendations
For Tenda AC6V2 versions through 15.03.06.50, update to a version later than 15.03.06.50 to resolve the issue. As a temporary workaround, consider restricting access to the fromAdvSetLanip module until a patch is available. Avoid using the
lanMask argument in the affected module until the issue is resolved.Exploit
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac6V2