A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the file /goform/DhcpListClient of the component Endpoint. Performing a manipulation of the argument page results in stack-based buffer overflow.
The attack can be initiated remotely. The exploit has been made public and could be used.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Tenda 4g06_Firmware
cpe:2.3:o:tenda:4g06_firmware:04.06.01.29:*:*:*:*:*:*:*
|
— | — |
|
Tenda 4g06
cpe:2.3:h:tenda:4g06:3.0:*:*:*:*:*:*:*
|
— | — |