
CVE-2024-2898 – Tenda AC7 SetStaticRouteCfg fromSetRouteStatic stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2898
26 Mar 2024 — A vulnerability classified as critical was found in Tenda AC7 15.03.06.44. Affected by this vulnerability is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/fromSetRouteStatic.md • CWE-121: Stack-based Buffer Overflow •

CVE-2024-2897 – Tenda AC7 WriteFacMac formWriteFacMac os command injection
https://notcve.org/view.php?id=CVE-2024-2897
26 Mar 2024 — A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/formWriteFacMac.md • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2024-2896 – Tenda AC7 WifiWpsStart formWifiWpsStart stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2896
26 Mar 2024 — A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. This issue affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/formWifiWpsStart.md • CWE-121: Stack-based Buffer Overflow •

CVE-2024-2895 – Tenda AC7 WifiWpsOOB formWifiWpsOOB stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2895
26 Mar 2024 — A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. This vulnerability affects the function formWifiWpsOOB of the file /goform/WifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow. The attack can be initiated remotely. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/formWifiWpsOOB.md • CWE-121: Stack-based Buffer Overflow •

CVE-2024-2894 – Tenda AC7 SetNetControlList formSetQosBand stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2894
26 Mar 2024 — A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. This affects the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/formSetQosBand.md • CWE-121: Stack-based Buffer Overflow •

CVE-2024-2893 – Tenda AC7 SetOnlineDevName formSetDeviceName stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2893
26 Mar 2024 — A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/formSetDeviceName_devName.md • CWE-121: Stack-based Buffer Overflow •

CVE-2024-2892 – Tenda AC7 setcfm formSetCfm stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2892
26 Mar 2024 — A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC7/v1/formSetCfm.md • CWE-121: Stack-based Buffer Overflow •

CVE-2024-2891 – Tenda AC7 QuickIndex formQuickIndex stack-based overflow
https://notcve.org/view.php?id=CVE-2024-2891
21 Mar 2024 — A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://packetstorm.news/files/id/177712 • CWE-121: Stack-based Buffer Overflow •

CVE-2023-41552
https://notcve.org/view.php?id=CVE-2023-41552
30 Aug 2023 — Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set. • https://github.com/peris-navince/founded-0-days/blob/main/form_fast_setting_wifi_set/1.md • CWE-787: Out-of-bounds Write •

CVE-2023-41555
https://notcve.org/view.php?id=CVE-2023-41555
30 Aug 2023 — Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet. • https://github.com/peris-navince/founded-0-days/blob/main/formWifiBasicSet/1.md • CWE-787: Out-of-bounds Write •