CVE-2017-9139: Buffer Overflow
Published May 21, 2017
·Updated
There is a stack-based buffer overflow on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). Crafted POST requests to an unspecified URL result in DoS, interrupting the HTTP service (used to login to the web UI of a router) for 1 to 2 seconds.
Affected Software
6 affected components
Tendacn F1200 Firmware<=1.2.0.19
Tendacn F1200
Tendacn Fh1202 Firmware<=1.2.0.19
Tendacn Fh1202
Tendacn F1202 Firmware<=1.2.0.19
Tendacn F1202
Event History
May 21, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9139?
CVE-2017-9139 is considered a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2017-9139?
To fix CVE-2017-9139, update the firmware of affected Tenda routers to version 1.2.0.20 or later.
3
Which Tenda router models are affected by CVE-2017-9139?
The affected Tenda router models include FH1202, F1202, and F1200 with firmware versions prior to 1.2.0.20.
4
What type of vulnerability is CVE-2017-9139?
CVE-2017-9139 is a stack-based buffer overflow vulnerability.
5
What impact does CVE-2017-9139 have on the affected routers?
CVE-2017-9139 can interrupt the HTTP service of the affected routers for 1 to 2 seconds.