CVE-2021-27706: Buffer Overflow
Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27706?
CVE-2021-27706 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2021-27706?
To mitigate CVE-2021-27706, it is recommended to update the firmware of Tenda G1 and G3 routers to a patched version that addresses this vulnerability.
Which devices are affected by CVE-2021-27706?
CVE-2021-27706 affects Tenda G1 and G3 routers specifically running firmware version V15.11.0.17(9502)_CN.
What type of vulnerability is CVE-2021-27706?
CVE-2021-27706 is a buffer overflow vulnerability that allows remote attackers to execute arbitrary code.
Are other firmware versions of Tenda routers affected by CVE-2021-27706?
No, only Tenda G1 and G3 routers running the specified firmware version are affected by CVE-2021-27706.