CVE-2024-10750 – Tenda i22 SysToo websReadEvent null pointer dereference
https://notcve.org/view.php?id=CVE-2024-10750
A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. • https://github.com/xiaobor123/tenda-vul-i22 https://vuldb.com/?ctiid.282919 https://vuldb.com/?id.282919 https://vuldb.com/?submit.435407 https://www.tenda.com.cn • CWE-476: NULL Pointer Dereference •
CVE-2024-10698 – Tenda AC6 SetOnlineDevName formSetDeviceName stack-based overflow
https://notcve.org/view.php?id=CVE-2024-10698
A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/theRaz0r/iot-mycve/blob/main/tenda_ac6_stackflow_formSetDeviceName/tenda_ac6_stackflow_formSetDeviceName.md https://vuldb.com/?ctiid.282866 https://vuldb.com/?id.282866 https://vuldb.com/?submit.434935 https://www.tenda.com.cn • CWE-121: Stack-based Buffer Overflow •
CVE-2024-10697 – Tenda AC6 API Endpoint WriteFacMac formWriteFacMac command injection
https://notcve.org/view.php?id=CVE-2024-10697
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument The leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/theRaz0r/iot-mycve/blob/main/tenda_ac6_rce_WriteFacMac/tenda_ac6_rce_WriteFacMac.md https://vuldb.com/?ctiid.282865 https://vuldb.com/?id.282865 https://vuldb.com/?submit.434934 https://www.tenda.com.cn • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2024-10662 – Tenda AC15 SetOnlineDevName formSetDeviceName stack-based overflow
https://notcve.org/view.php?id=CVE-2024-10662
A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/theRaz0r/iot-mycve/blob/main/tenda_ac15_stackflow_formSetDeviceName/tenda_ac15_stackflow_formSetDeviceName.md https://vuldb.com/?ctiid.282677 https://vuldb.com/?id.282677 https://vuldb.com/?submit.434933 https://www.tenda.com.cn • CWE-121: Stack-based Buffer Overflow •
CVE-2024-10661 – Tenda AC15 SetDlnaCfg stack-based overflow
https://notcve.org/view.php?id=CVE-2024-10661
A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation of the argument scanList leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/theRaz0r/iot-mycve/blob/main/tenda_ac15_stackflow_formDLNAserver/tenda_ac15_stackflow_formDLNAserver.md https://vuldb.com/?ctiid.282676 https://vuldb.com/?id.282676 https://vuldb.com/?submit.434932 https://www.tenda.com.cn • CWE-121: Stack-based Buffer Overflow •