A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function formSetPPTPServer. The manipulation of the argument startIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252129 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
2024-01-26T15:15:08.537
2024-11-21T08:47:45.600
Modified
CVSSv3.1: 4.7 (MEDIUM)
AV:N/AC:L/Au:M/C:P/I:P/A:P
6.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tenda | ac10u_firmware | 15.03.06.49_multi_tde01 | Yes |
Hardware | tenda | ac10u | - | No |