9.8

CVE-2020-13391

Exploit
An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetSpeedWan speed_dir parameter for a POST request, a value is directly used in a sprintf to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tendacn ≫ Ac6 Firmware Version v15.03.05.19_multi_td01
   Tendacn ≫ Ac6 Version 1.0
Tendacn ≫ Ac9 Firmware Version v15.03.05.19(6318)
   Tendacn ≫ Ac9 Version 1.0
Tendacn ≫ Ac15 Firmware Version v15.03.05.19_multi_td01
   Tendacn ≫ Ac15 Version 1.0
Tendacn ≫ Ac18 Firmware Version v15.03.05.19(6318)
   Tendacn ≫ Ac18 Version -
Tendacn ≫ Ac9 Firmware Version v15.03.06.42_multi
   Tendacn ≫ Ac9 Version 3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.55% 0.83
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://joel-malwarebenchmark.github.io
Third Party Advisory
Exploit
https://joel-malwarebenchmark.github.io/blog/2020/04/28/cve-2020-13391-Tenda-vulnerability/
Third Party Advisory
Exploit