CVE-2024-11650 – Tenda i9 GetIPTV websReadEvent null pointer dereference
https://notcve.org/view.php?id=CVE-2024-11650
A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/xiaobor123/tenda-vul-i9 https://vuldb.com/?ctiid.285971 https://vuldb.com/?id.285971 https://vuldb.com/?submit.446592 https://www.tenda.com.cn • CWE-404: Improper Resource Shutdown or Release CWE-476: NULL Pointer Dereference •
CVE-2024-11248 – Tenda AC10 SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow
https://notcve.org/view.php?id=CVE-2024-11248
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://tasty-foxtrot-3a8.notion.site/Tenda-AC10v4-formSetRebootTimer-stack-overflow-13d0448e619580bf8ab1df7cfb6c018b https://vuldb.com/?ctiid.284684 https://vuldb.com/?id.284684 https://vuldb.com/?submit.443204 https://www.tenda.com.cn • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-121: Stack-based Buffer Overflow •
CVE-2024-11061 – Tenda AC10 fast_setting_wifi_set FUN_0044db3c stack-based overflow
https://notcve.org/view.php?id=CVE-2024-11061
A vulnerability classified as critical was found in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function FUN_0044db3c of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://tasty-foxtrot-3a8.notion.site/Tenda-AC10v4-FUN_0044db3c-stack-overflow-13a0448e619580ae96fee2899545e159 https://vuldb.com/?ctiid.283807 https://vuldb.com/?id.283807 https://vuldb.com/?submit.440825 https://www.tenda.com.cn • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-121: Stack-based Buffer Overflow •
CVE-2024-11056 – Tenda AC10 WifiExtraSet FUN_0046AC38 stack-based overflow
https://notcve.org/view.php?id=CVE-2024-11056
A vulnerability, which was classified as critical, was found in Tenda AC10 16.03.10.13. Affected is the function FUN_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://tasty-foxtrot-3a8.notion.site/Tenda-AC10v4-stack-overflow-1380448e619580409bb1e1ac85f45570 https://vuldb.com/?ctiid.283800 https://vuldb.com/?id.283800 https://vuldb.com/?submit.439358 https://www.tenda.com.cn • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-121: Stack-based Buffer Overflow •
CVE-2024-10750 – Tenda i22 SysToo websReadEvent null pointer dereference
https://notcve.org/view.php?id=CVE-2024-10750
A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. • https://github.com/xiaobor123/tenda-vul-i22 https://vuldb.com/?ctiid.282919 https://vuldb.com/?id.282919 https://vuldb.com/?submit.435407 https://www.tenda.com.cn • CWE-476: NULL Pointer Dereference •