Tenda AC500是中国腾达(Tenda)公司的一个千兆端口访问控制器。 Tenda AC500 2.0.1.9(1307) 版本存在安全漏洞,该漏洞源于 /goform/setcfm 文件的 formSetCfm 方法的 funcpara1 参数存在缓冲区溢出问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-3905 | 8.8 HIGH | Tenda AC500 execCommand R7WebsSecurityHandler stack-based overflow |
| CVE-2024-3906 | 8.8 HIGH | Tenda AC500 QuickIndex formQuickIndex stack-based overflow |
| CVE-2024-3909 | 8.8 HIGH | Tenda AC500 execCommand formexeCommand stack-based overflow |
| CVE-2024-3910 | 8.8 HIGH | Tenda AC500 DhcpListClient fromDhcpListClient stack-based overflow |
| CVE-2024-3908 | 6.3 MEDIUM | Tenda AC500 WriteFacMac formWriteFacMac command injection |
No comments yet