CVE-2024-2901: Tenda AC7 openSchedWifi setSchedWifi stack-based overflow
A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257944. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2901?
CVE-2024-2901 is classified as a critical vulnerability.
How does CVE-2024-2901 affect Tenda AC7?
CVE-2024-2901 affects the setSchedWifi function in Tenda AC7 firmware version 15.03.06.44.
What type of exploit can be executed via CVE-2024-2901?
CVE-2024-2901 can lead to a stack-based buffer overflow due to argument manipulation.
What steps can be taken to mitigate CVE-2024-2901?
To mitigate CVE-2024-2901, users should install the latest firmware updates for Tenda AC7.
Is there a workaround for CVE-2024-2901 if I cannot update my firmware?
Currently, there are no documented workarounds for CVE-2024-2901 aside from updating to a patched version.