CVE-2024-4065: Tenda AC8 SetRebootTimer formSetRebootTimer stack-based overflow
A vulnerability was found in Tenda AC8 16.03.34.09. It has been rated as critical. This issue affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261791. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4065?
CVE-2024-4065 has been rated as critical due to its potential to trigger a stack-based buffer overflow.
How is CVE-2024-4065 exploited?
CVE-2024-4065 can be exploited by manipulating the argument rebootTime in the formSetRebootTimer function.
What devices are affected by CVE-2024-4065?
CVE-2024-4065 specifically affects Tenda AC8 firmware version 16.03.34.09.
How can I fix CVE-2024-4065?
To fix CVE-2024-4065, you should update the Tenda AC8 firmware to the latest secure version provided by Tenda.
What are the potential risks of CVE-2024-4065?
The risks associated with CVE-2024-4065 include remote code execution and unauthorized access to the affected device.