First published: Fri May 07 2021(Updated: )
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allows attackers to execute arbitrary code on the system via a crafted post request. This occurs when input vector controlled by malicious attack get copied to the stack variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC11 Firmware | <=02.03.01.104_cn | |
Tenda AC11 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31756 is considered to be a high severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2021-31756, upgrade the Tenda AC11 firmware to a version above 02.03.01.104_CN.
CVE-2021-31756 is a stack buffer overflow vulnerability found in the /gofrom/setwanType endpoint.
Devices running Tenda AC11 firmware version 02.03.01.104_CN and below are affected by CVE-2021-31756.
Yes, CVE-2021-31756 can be exploited remotely by sending a crafted post request to the vulnerable device.