CVE-2024-7582: Buffer Overflow
A vulnerability classified as critical was found in Tenda i22 1.0.0.3(4687). This vulnerability affects the function formApPortalAccessCodeAuth of the file /goform/apPortalAccessCodeAuth. The manipulation of the argument accessCode/data/acceInfo leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7582?
CVE-2024-7582 is classified as a critical vulnerability.
How does CVE-2024-7582 affect Tenda i22 devices?
CVE-2024-7582 affects the formApPortalAccessCodeAuth function, leading to potential buffer overflow.
What are the implications of exploiting CVE-2024-7582?
Exploiting CVE-2024-7582 could allow an attacker to execute arbitrary code or crash the device.
How do I fix CVE-2024-7582?
To fix CVE-2024-7582, users should update their Tenda i22 firmware to the latest version provided by the manufacturer.
What versions of Tenda i22 are affected by CVE-2024-7582?
CVE-2024-7582 specifically affects Tenda i22 firmware version 1.0.0.3(4687).