CVE-2021-31755: Tenda AC11 Router Stack Buffer Overflow Vulnerability
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
Other sources
Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote/WAN web management on the router to prevent external access to the /goform/setmac endpoint.
Tenda AC11 web management remote_management = disabled - Compensating control
Block or filter HTTP POST requests to /goform/setmac at the network edge (firewall, WAF, or router ACLs) and restrict access to the router management interface to trusted IP addresses only.
- Operational
Monitor Tenda vendor advisories for a firmware release that fixes the vulnerability (devices with firmware through 02.03.01.104_CN are vulnerable) and apply the vendor firmware update to affected devices as soon as a fixed version is published.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31755?
CVE-2021-31755 has a CVSS base score indicating a high severity level due to its potential for remote code execution.
How do I fix CVE-2021-31755?
To mitigate CVE-2021-31755, upgrade the firmware of your Tenda AC11 device to a version newer than 02.03.01.104_CN.
What type of vulnerability is CVE-2021-31755?
CVE-2021-31755 is a stack buffer overflow vulnerability that can allow arbitrary code execution.
Which devices are affected by CVE-2021-31755?
CVE-2021-31755 affects Tenda AC11 devices running firmware versions up to and including 02.03.01.104_CN.
What can an attacker do exploiting CVE-2021-31755?
An attacker can exploit CVE-2021-31755 to execute arbitrary code on the affected Tenda AC11 devices.