PT-2024-6578 · Tenda · Tenda Ax1803

Published

2024-04-02

·

Updated

2025-03-12

·

CVE-2024-30620

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Tenda AX1803 version 1.0.0.1
Description: The issue is related to a stack overflow in the fromAdvSetMacMtuWan function, specifically via the serviceName parameter. This can be exploited by sending specially crafted POST requests to the /goform/AdvSetMacMtuWan endpoint, potentially allowing a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations: For Tenda AX1803 version 1.0.0.1, restrict WAN access and update the firmware to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the /goform/AdvSetMacMtuWan endpoint and avoiding the use of the serviceName parameter until a patch is available.

Exploit

Fix

Memory Corruption

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07723
CVE-2024-30620

Affected Products

Tenda Ax1803