xiezhihua-1127/Tenda-Stack-Overflow

xiezhihua-1127/Tenda-Stack-Overflow

Releases0
A stack-based buffer overflow vulnerability exists in the formPPPEdit interface (via the encodename parameter) exposed through the web management interface (/boaform/formPPPEdit) of the Tenda HG10 router.

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH9 HIGH

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.