PT-2026-28687 · Tenda · Tenda Ac6
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC6 version 15.03.05.16
Description
A flaw exists in the Tenda AC6 device that allows for a stack-based buffer overflow. This occurs through the manipulation of the
PPPOEPassword argument within the formQuickIndex function, located in the file /goform/QuickIndex, via a POST request handler. The issue is remotely exploitable and a public exploit is available.Recommendations
Update to a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the /goform/QuickIndex file.
Avoid using the
PPPOEPassword parameter in the affected function until the issue is resolved.Exploit
Correção
Memory Corruption
Buffer Overflow
Stack Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tenda Ac6