CVE-2024-8226

A vulnerability has been found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:o1_firmware:1.0.0.7\(10648\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:o1:-:*:*:*:*:*:*:*

History

29 Aug 2024, 00:13

Type Values Removed Values Added
CVSS v2 : 9.0
v3 : 8.8
v2 : 9.0
v3 : 9.8
CWE CWE-787
CPE cpe:2.3:h:tenda:o1:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:o1_firmware:1.0.0.7\(10648\):*:*:*:*:*:*:*
First Time Tenda o1 Firmware
Tenda
Tenda o1
References () https://github.com/abcdefg-png/AHU-IoT-vulnerable/blob/main/Tenda/web-bridge/O1V1.1/formSetCfm.md - () https://github.com/abcdefg-png/AHU-IoT-vulnerable/blob/main/Tenda/web-bridge/O1V1.1/formSetCfm.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.275935 - () https://vuldb.com/?ctiid.275935 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.275935 - () https://vuldb.com/?id.275935 - VDB Entry
References () https://vuldb.com/?submit.394009 - () https://vuldb.com/?submit.394009 - VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product

28 Aug 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en Tenda O1 1.0.0.7(10648) y clasificada como crítica. La función formSetCfm del archivo /goform/setcfm es afectada por esta vulnerabilidad. La manipulación del argumento funcpara1 provoca un desbordamiento del búfer basado en pila. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera.

28 Aug 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-28 00:15

Updated : 2024-08-29 00:13


NVD link : CVE-2024-8226

Mitre link : CVE-2024-8226

CVE.ORG link : CVE-2024-8226


JSON object : View

Products Affected

tenda

  • o1
  • o1_firmware
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow