An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTenda Ac11
HWTendaall versionsTenda Ac11 Firmware
OSTenda≤ 02.03.01.104_cn
CISA KEV — detailsi
- Vendori
- Tenda
- Producti
- AC11 Router
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- November 17, 2021(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 17 listopada 2021
Tags
RCEMemory
Related vulnerabilities
CVE-2021-46321CRITICAL9.8PL ✓same product
Stack buffer overflow w module wifiBasicCfg routera Tenda AC11
CVE-2021-46263CRITICAL9.8PL ✓same product
Stack buffer overflow w module wifiTime routera Tenda AC11
CVE-2021-46264CRITICAL9.8PL ✓same product
Stack buffer overflow w routerze Tenda AC11 — moduł onlineList
CVE-2021-46265CRITICAL9.8PL ✓same product
Stack buffer overflow w routerze Tenda AC11 — DoS przez moduł wanBasicCfg
CVE-2021-46262CRITICAL9.8PL ✓same product
Stack buffer overflow w module PPPoE routera Tenda AC11