CVE-2021-27707: Buffer Overflow
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27707?
CVE-2021-27707 is considered a high severity vulnerability due to its capability to allow remote code execution.
How do I fix CVE-2021-27707?
To fix CVE-2021-27707, upgrade the firmware of Tenda G1 and G3 routers to a version that addresses this buffer overflow vulnerability.
Which devices are affected by CVE-2021-27707?
CVE-2021-27707 affects Tenda G1 and G3 routers running firmware v15.11.0.17(9502)_CN.
What type of attack does CVE-2021-27707 enable?
CVE-2021-27707 enables remote attackers to execute arbitrary code through crafted requests.
What is the impact of exploiting CVE-2021-27707?
Exploiting CVE-2021-27707 can lead to unauthorized access and control over the affected router, potentially compromising the network.