CVE-2024-4240: Tenda W9 formQosManageDouble_user stack-based overflow
A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQosManageDoubleuser. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-262131. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4240?
The severity of CVE-2024-4240 has been classified as critical.
How does CVE-2024-4240 affect Tenda W9 devices?
CVE-2024-4240 affects Tenda W9 devices by allowing a stack-based buffer overflow via manipulation of the ssidIndex argument.
Can CVE-2024-4240 be exploited remotely?
Yes, CVE-2024-4240 can be exploited remotely, making it particularly dangerous.
How do I fix CVE-2024-4240?
To fix CVE-2024-4240, it is recommended to update the Tenda W9 firmware to the latest version available.
What versions of Tenda W9 are affected by CVE-2024-4240?
Tenda W9 firmware version 1.0.0.7(4456) is affected by CVE-2024-4240.