CVE-2024-2808: Tenda AC15 QuickIndex formQuickIndex stack-based overflow
A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20multi. This issue affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257663. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2808?
CVE-2024-2808 is classified as a critical vulnerability due to its potential for exploitation via stack-based buffer overflow.
How do I fix CVE-2024-2808?
To mitigate CVE-2024-2808, update the Tenda AC15 firmware to the latest version provided by the manufacturer.
What is the impact of CVE-2024-2808?
The impact of CVE-2024-2808 could lead to denial of service or potentially allow remote code execution due to the buffer overflow.
Which software versions are affected by CVE-2024-2808?
CVE-2024-2808 affects Tenda AC15 firmware versions 15.03.05.18 and 15.03.05.20_multi.
How does CVE-2024-2808 exploit stack-based buffer overflow?
CVE-2024-2808 exploits stack-based buffer overflow by manipulating the PPPOEPassword argument in the formQuickIndex function.