Tenda.W30E.setIPv6Status.Parameter.Stack.Overflow

description-logoDescription

This indicates an attack attempt to exploit a Stack Overflow vulnerability in Tenda W30E.
The vulnerability is caused by an HTTP POST parameter 'wanAddr' where the parameter size is not handled properly and may be set to an arbitrary length, thus leading to a stack overflow. An attacker can exploit this with a constructed payload to gain system control.

affected-products-logoAffected Products

Tenda W30E version 16.01.0.12(4843)

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-03-14 27.749