PT-2025-3476 · Tenda · Tenda Ac18

Published

2024-12-28

·

Updated

2025-01-18

·

CVE-2024-57582

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC18 version V15.03.05.19
Description The issue is related to a stack overflow in the formSetPPTPServer function when handling the startIP parameter. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Tenda AC18 version V15.03.05.19, consider disabling the formSetPPTPServer function or restricting access to the startIP parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-01544
CVE-2024-57582

Affected Products

Tenda Ac18