CVE-2024-4252: Tenda i22 formSetUrlFilterRule stack-based overflow
A vulnerability classified as critical has been found in Tenda i22 1.0.0.3(4687). This affects the function formSetUrlFilterRule. The manipulation of the argument groupIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-262143. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4252?
CVE-2024-4252 has been classified as a critical vulnerability.
How does CVE-2024-4252 affect the Tenda i22?
CVE-2024-4252 affects the Tenda i22 by allowing a stack-based buffer overflow due to manipulation of the argument groupIndex.
Can CVE-2024-4252 be exploited remotely?
Yes, CVE-2024-4252 can be exploited remotely.
What is the affected version for CVE-2024-4252?
CVE-2024-4252 affects Tenda i22 firmware version 1.0.0.3(4687).
How can I mitigate the risks associated with CVE-2024-4252?
To mitigate the risks associated with CVE-2024-4252, it's recommended to update the Tenda i22 firmware to a patched version as it becomes available.