CVE-2024-10351 HIGH

CVE-2024-10351: Tenda RX9 Pro POST Request setMacFilterCfg sub_424CE0 stack-based overflow

Vendor Tenda
Product RX9 Pro
Weakness CWE-121
Published October 24, 2024
Last update October 25, 2024

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Key dates

02Disclosure timeline

October 24, 2024 CVE published
October 25, 2024 Record updated