CVE-2024-2809: Tenda AC15 SetFirewallCfg formSetFirewallCfg stack-based overflow
A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20multi. Affected is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257664. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2809?
CVE-2024-2809 is classified as a critical vulnerability.
How do I fix CVE-2024-2809?
To fix CVE-2024-2809, update your Tenda AC15 router firmware to a version that addresses this vulnerability.
What type of vulnerability is CVE-2024-2809?
CVE-2024-2809 is a stack-based buffer overflow vulnerability.
What is affected by CVE-2024-2809?
CVE-2024-2809 affects the Tenda AC15 firmware versions 15.03.05.18 and 15.03.05.20_multi.
What impact does CVE-2024-2809 have?
The exploitation of CVE-2024-2809 can lead to potential unauthorized access and control over the affected device.