First published: Wed Apr 24 2024(Updated: )
A vulnerability classified as critical has been found in Tenda TX9 22.03.02.10. This affects the function sub_42CB94 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda TX9 | ||
All of | ||
Tenda Tx9 Pro Firmware | =22.03.02.10 | |
Tenda TX9 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4112 is classified as a critical vulnerability.
CVE-2024-4112 affects the function sub_42CB94 in Tenda TX9 by allowing stack-based buffer overflow.
Yes, CVE-2024-4112 can be exploited remotely, enabling attackers to manipulate the argument list.
The vulnerability CVE-2024-4112 is found in Tenda TX9 firmware version 22.03.02.10.
To mitigate CVE-2024-4112, users should update their Tenda TX9 devices to a patched firmware version.