CRITICAL

CVE-2021-31755

Tenda Ac11 Firmware 2021-05-07 CVSS v3.1
CVSS
9.8
KEV

Description

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

Summary dbcve.org

Stack buffer overflow vulnerability in the /goform/setmac endpoint of Tenda AC11 routers allows remote attackers to overwrite stack memory and execute arbitrary code via a crafted POST request with oversized input.

Mitigation

Update to patched firmware if available; otherwise restrict administrative interface access to trusted networks to prevent exploitation of this critical flaw.

Proof of Concept

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

86.89%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE