RSS   Vulnerabilities for 'Ac10 firmware'   RSS

2018-09-01
 
CVE-2018-16334

CWE-78
 

 
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.

 
 
CVE-2018-16333

CWE-119
 

 
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server. While processing the ssid parameter for a POST request, the value is directly used in a sprintf call to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.

 
2018-07-21
 
CVE-2018-14492

CWE-119
 

 
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.

 

 >>> Vendor: Tendacn 11 Products
F1202 firmware
F1200 firmware
Fh1202 firmware
Ac15 firmware
Ac18 firmware
Ac9 firmware
Ac10 firmware
Ac7 firmware
D152 firmware
Adsl firmware
N301 firmware


Copyright 2024, cxsecurity.com

 

Back to Top