CVE-2018-14559: Buffer Overflow
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)CN(AC9), and AC10 devices with firmware through V15.03.06.23CN(AC10). A buffer overflow vulnerability exists in the router's web server (httpd). When processing the list parameters for a post request, the value is directly written with sprintf to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-14559.
Which Tenda devices are affected by this vulnerability?
The Tenda AC7, AC9, and AC10 devices are affected by this vulnerability.
What is the severity of CVE-2018-14559?
The severity of CVE-2018-14559 is rated as high.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-119.
Is there a fix available for this vulnerability?
Yes, updating the firmware to the latest version provided by Tenda will fix this vulnerability.