9.8
CVSSv3

CVE-2024-2856

Published: 24/03/2024 Updated: 11/04/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257780. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tenda ac10_firmware 16.03.10.13

tenda ac10_firmware 16.03.10.20

Github Repositories

Tenda AC10 Router exploit stack-based buffer overflow

CVE-2024-2856-Stack-overflow-EXP Tenda AC10 Router exploit stack-based buffer overflow