Description
A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument endIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257601 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27708 | A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument endIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257601 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
References
History
Thu, 12 Dec 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac10u Tenda ac10u Firmware |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:h:tenda:ac10u:1.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac10u_firmware:15.03.06.48:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda ac10u Tenda ac10u Firmware |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-02T13:57:14.115Z
Reserved: 2024-03-21T15:17:47.961Z
Link: CVE-2024-2764
Updated: 2024-08-02T13:57:09.903Z
Status : Analyzed
Published: 2024-03-21T21:15:11.177
Modified: 2024-12-12T17:32:10.783
Link: CVE-2024-2764
No data.
OpenCVE Enrichment
No data.
EUVD