A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.
The vulnerability exists in the formWifiBasicSet function, which improperly handles the 'security' parameter transmitted by the attacker. The lack of proper validation of input data length causes a stack overflow, overwriting critical memory structures. The attacker can craft an appropriate payload and send it remotely without authentication, thereby gaining control over program execution flow and the ability to run arbitrary code.
An attacker can remotely execute arbitrary code (RCE) with the privileges of the process handling the request, which in practice means complete takeover of the router — including network traffic eavesdropping, configuration changes, malicious software installation, or using the device as an entry point to the internal network.
Apply patches available from the manufacturer according to the references. Until the fix is deployed, it is recommended to restrict access to the device management interface only to trusted IP addresses and block access to the admin panel from the WAN side.
Tenda AC7 with software version V15.03.06.44
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTenda Ac7
HWTenda1.0Tenda Ac7 Firmware
OSTenda15.03.06.44
Related vulnerabilities
Command Injection w routerach Tenda AC7/AC9/AC10 via setUsbUnload
Stack buffer overflow w Tenda AC7 via parametr wanMTU
Stack buffer overflow w Tenda AC7 via parametr mac (/goform/AdvSetMacMtuWan)
Stack buffer overflow w Tenda AC7 — interfejs AdvSetMacMtuWan
Stack buffer overflow w Tenda AC7 — RCE przez parametr wanSpeed