PT-2024-35144 · Tenda · Tenda Ac6V2

·

CVE-2024-52274

·

Published

2024-12-04

·

Updated

2025-05-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC6V2 versions through 15.03.06.50
Description The issue is a stack-based buffer overflow vulnerability in the setDoubleL2tpConfig->guest ip check modules, allowing buffer overflows. This vulnerability affects Tenda AC6V2 and can be exploited for remote code execution.
Recommendations For Tenda AC6V2 versions through 15.03.06.50, update the firmware to a version later than 15.03.06.50 to resolve the issue. As a temporary workaround, consider restricting access to the setDoubleL2tpConfig module and the guest ip check function until a patch is available. Avoid using the mask argument in the affected modules until the issue is resolved.

Exploit

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52274

Affected Products

Tenda Ac6V2