CVE-2018-14492

Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tendacn:ac7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tendacn:ac7:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tendacn:ac9_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tendacn:ac9:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tendacn:ac10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tendacn:ac10:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tendacn:ac15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tendacn:ac15:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tendacn:ac18_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tendacn:ac18:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:49

Type Values Removed Values Added
References () https://github.com/ZIllR0/Routers/blob/master/Tendaoob1.md - Exploit, Third Party Advisory () https://github.com/ZIllR0/Routers/blob/master/Tendaoob1.md - Exploit, Third Party Advisory

Information

Published : 2018-07-21 12:29

Updated : 2024-11-21 03:49


NVD link : CVE-2018-14492

Mitre link : CVE-2018-14492

CVE.ORG link : CVE-2018-14492


JSON object : View

Products Affected

tendacn

  • ac7
  • ac15
  • ac10_firmware
  • ac9_firmware
  • ac18
  • ac7_firmware
  • ac9
  • ac18_firmware
  • ac15_firmware
  • ac10
CWE
CWE-787

Out-of-bounds Write