CVE-2024-2806: Tenda AC15 addWifiMacFilter stack-based overflow
A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceId/deviceMac leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257661 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2806?
CVE-2024-2806 is classified as a critical vulnerability due to its potential for stack-based buffer overflow.
How do I fix CVE-2024-2806?
To fix CVE-2024-2806, it is recommended to update the Tenda AC15 firmware to the latest available version.
What software versions are affected by CVE-2024-2806?
CVE-2024-2806 affects Tenda AC15 firmware versions 15.03.05.18 and 15.03.05.20_multi.
What are the potential consequences of CVE-2024-2806?
Exploitation of CVE-2024-2806 could allow attackers to execute arbitrary code on the vulnerable device.
Who is affected by CVE-2024-2806?
Users of the Tenda AC15 router running the specified firmware versions are affected by CVE-2024-2806.