Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-42659


There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9 V1.0 V15.03.02.19(6318) and Tenda AC9 V3.0 V15.03.06.42_multi. When setting the virtual service, the httpd program will crash and exit when the super-long list parameter occurs.


Published

2022-05-24T12:15:07.590

Last Modified

2024-11-21T06:27:55.827

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tenda ac9_firmware 15.03.05.19\(6318\) Yes
Hardware tenda ac9 1.0 No
Operating System tenda ac9_firmware 15.03.06.42_multi Yes
Hardware tenda ac9 3.0 No

References