A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-33057 A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 01 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda rx9 Pro
Weaknesses CWE-787
CPEs cpe:2.3:h:tenda:rx9_pro:-:*:*:*:*:*:*:*
Vendors & Products Tenda rx9 Pro

Fri, 25 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda rx9 Pro Firmware
CPEs cpe:2.3:o:tenda:rx9_pro_firmware:22.03.02.20:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda rx9 Pro Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Oct 2024 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Title Tenda RX9 Pro POST Request setMacFilterCfg sub_424CE0 stack-based overflow
Weaknesses CWE-121
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-10-25T20:50:14.294Z

Reserved: 2024-10-24T15:34:29.365Z

Link: CVE-2024-10351

cve-icon Vulnrichment

Updated: 2024-10-25T20:50:03.820Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T00:15:02.533

Modified: 2024-11-01T16:15:23.800

Link: CVE-2024-10351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.