CVE-2024-2856 – Tenda AC10 SetSysTimeCfg fromSetSysTime stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2856
A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC10/V16.03.10.13/fromSetSysTime.md https://vuldb.com/?ctiid.257780 https://vuldb.com/?id.257780 https://vuldb.com/?submit.299741 • CWE-121: Stack-based Buffer Overflow •
CVE-2023-45479
https://notcve.org/view.php?id=CVE-2023-45479
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the list parameter in the function sub_49E098. Se descubrió que la versión Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn contenía un desbordamiento de pila a través del parámetro de lista en la función sub_49E098. • https://github.com/l3m0nade/IOTvul/blob/master/assets/sub_49E098_code.png https://github.com/l3m0nade/IOTvul/blob/master/sub_49E098.md • CWE-787: Out-of-bounds Write •
CVE-2023-45480
https://notcve.org/view.php?id=CVE-2023-45480
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the src parameter in the function sub_47D878. Se descubrió que la versión Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn contenía un desbordamiento de pila a través del parámetro src en la función sub_47D878. • https://github.com/l3m0nade/IOTvul/blob/master/assets/sub_47d878_code.png https://github.com/l3m0nade/IOTvul/blob/master/sub_47D878.md • CWE-787: Out-of-bounds Write •
CVE-2023-45481
https://notcve.org/view.php?id=CVE-2023-45481
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg. Se descubrió que la versión Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn contenía un desbordamiento de pila a través del parámetro firewallEn en la función SetFirewallCfg. • https://github.com/l3m0nade/IOTvul/blob/master/SetFirewallCfg.md https://github.com/l3m0nade/IOTvul/blob/master/assets/setFirewallCfg_code.png • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •
CVE-2023-45482
https://notcve.org/view.php?id=CVE-2023-45482
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info. Se descubrió que la versión Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn contenía un desbordamiento de pila a través del parámetro urls en la función get_parentControl_list_Info. • https://github.com/l3m0nade/IOTvul/blob/master/assets/get_parentControl_list_Info_code.png https://github.com/l3m0nade/IOTvul/blob/master/get_parentControl_list_Info.md • CWE-787: Out-of-bounds Write •