CVE-2020-20746: Buffer Overflow
Published Sep 30, 2021
·Updated
A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.
Affected Software
2 affected components
Tendacn Ac9 Firmware=15.03.06.60_en
Tendacn Ac9=3.0
Event History
Sep 30, 2021
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-20746.
2
What is the severity of CVE-2020-20746?
The severity of CVE-2020-20746 is high with a CVSS score of 7.2.
3
How does CVE-2020-20746 affect Tenda AC9 firmware version 15.03.06.60_EN?
CVE-2020-20746 allows remote attackers to execute arbitrary code or cause a denial of service (DoS) on Tenda AC9 firmware version 15.03.06.60_EN through a crafted POST request to /goform/SetStaticRouteCfg.
4
Is Tenda AC9 firmware version 3.0 affected by CVE-2020-20746?
No, Tenda AC9 firmware version 3.0 is not affected by CVE-2020-20746.
5
How can I fix CVE-2020-20746?
To fix CVE-2020-20746, it is recommended to update Tenda AC9 firmware to a version that is not vulnerable.