CRITICAL
CVE-2021-31755
CVSS
9.8
KEV
Description
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
Summary dbcve.org
Stack buffer overflow vulnerability in the /goform/setmac endpoint of Tenda AC11 routers allows remote attackers to overwrite stack memory and execute arbitrary code via a crafted POST request with oversized input.
Mitigation
Update to patched firmware if available; otherwise restrict administrative interface access to trusted networks to prevent exploitation of this critical flaw.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
86.89%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.