Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.
The vulnerability occurs in the fromSetRouteStatic function, which improperly validates the length of data passed through the list parameter. An attacker can send a specially crafted network request with an excessively long parameter value, leading to stack buffer overflow (CWE-121 — stack-based buffer overflow). Exploitation is possible remotely, without authentication and without user interaction.
A successful attack can lead to remote code execution (RCE) on the device, and thus to complete takeover of the router, violation of data confidentiality and integrity, and potential blocking of network access.
Apply patches available from the manufacturer according to the references. Until an update is released, it is recommended to restrict access to the device's administrative panel only to trusted IP addresses and to isolate the device from the public Internet.
Tenda AC8 with firmware version V16.03.34.06
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTenda Ac8
HWTendaall versionsTenda Ac8 Firmware
OSTenda16.03.34.06
Related vulnerabilities
Buffer overflow w Tenda AC8V4 — stack overflow w funkcji get_parentControl_list_Info
Tenda AC8V4 — stack overflow w parametrze shareSpeed (RCE)
Tenda AC8V4 — stack overflow przez parametr shareSpeed (RCE)
Tenda AC8V4 — stack-based buffer overflow w funkcji WifiExtraSet
Tenda AC8v4 — stack overflow w funkcji setSchedWifi (schedEndTime)