An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routing functionality.
The vulnerability (classified as CWE-940 — Improper Verification of Source of a Communication Channel) is found in the device's Routing functionality. A remote attacker can, without any privileges or user interaction, send a specially crafted network request that leads to arbitrary code execution on the device. The network attack vector (AV:N) with no authentication requirements (PR:N) and no user interaction (UI:N) makes the attack exceptionally simple to carry out.
An attacker can gain full control over the device, including reading and modifying its configuration, intercepting network traffic, or using the router as an entry point to the local network (lateral movement).
Apply patches available from the manufacturer according to the references. Until an update is released, it is recommended to restrict access to the device management interface to trusted hosts only and disable remote management over the Internet.
Tenda AX2 Pro firmware version V16.03.29.48_cn
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTenda Ax2 Pro
HWTendaall versionsTenda Ax2 Pro Firmware
OSTenda16.03.29.48_cn
Related vulnerabilities
Tenda AC11: stack buffer overflow w /goform/setmac umożliwia RCE
Command injection w Tenda AC15 – zdalne wykonanie poleceń systemowych
Command Injection w routerach Tenda AC7/AC9/AC10 via setUsbUnload
Stack buffer overflow w Tenda AC7 via parametr wanMTU
Stack buffer overflow w Tenda AC7 — interfejs AdvSetMacMtuWan