First published: Wed Apr 14 2021(Updated: )
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tendacn G1 Firmware | =v15.11.0.17\(9502\)_cn | |
Tendacn G1 Firmware | ||
Tenda G3 Firmware | =v15.11.0.17\(9502\)_cn | |
Tenda G3 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27707 is considered a high severity vulnerability due to its capability to allow remote code execution.
To fix CVE-2021-27707, upgrade the firmware of Tenda G1 and G3 routers to a version that addresses this buffer overflow vulnerability.
CVE-2021-27707 affects Tenda G1 and G3 routers running firmware v15.11.0.17(9502)_CN.
CVE-2021-27707 enables remote attackers to execute arbitrary code through crafted requests.
Exploiting CVE-2021-27707 can lead to unauthorized access and control over the affected router, potentially compromising the network.