Tenda AC7是中国腾达(Tenda)公司的一款无线路由器。 Tenda AC7 15.03.06.44 版本存在安全漏洞,该漏洞源于 formSetQosBand 方法的 list 参数存在缓冲区溢出漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-2891 | 8.8 HIGH | Tenda AC7 QuickIndex formQuickIndex stack-based overflow |
| CVE-2024-2892 | 8.8 HIGH | Tenda AC7 setcfm formSetCfm stack-based overflow |
| CVE-2024-2893 | 8.8 HIGH | Tenda AC7 SetOnlineDevName formSetDeviceName stack-based overflow |
| CVE-2024-2895 | 8.8 HIGH | Tenda AC7 WifiWpsOOB formWifiWpsOOB stack-based overflow |
| CVE-2024-2896 | 8.8 HIGH | Tenda AC7 WifiWpsStart formWifiWpsStart stack-based overflow |
| CVE-2024-2898 | 8.8 HIGH | Tenda AC7 SetStaticRouteCfg fromSetRouteStatic stack-based overflow |
| CVE-2024-2899 | 8.8 HIGH | Tenda AC7 WifiExtraSet fromSetWirelessRepeat stack-based overflow |
| CVE-2024-2900 | 8.8 HIGH | Tenda AC7 saveParentControlInfo stack-based overflow |
| CVE-2024-2901 | 8.8 HIGH | Tenda AC7 openSchedWifi setSchedWifi stack-based overflow |
| CVE-2024-2902 | 8.8 HIGH | Tenda AC7 WifiGuestSet fromSetWifiGusetBasic stack-based overflow |
| CVE-2024-2903 | 8.8 HIGH | Tenda AC7 GetParentControlInfo stack-based overflow |
| CVE-2024-2897 | 6.3 MEDIUM | Tenda AC7 WriteFacMac formWriteFacMac os command injection |
No comments yet