10

CVE-2021-31755

Warnung
Medienbericht
Exploit
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TendaAc11 Firmware Version <= 02.03.01.104_cn
   TendaAc11 Version-

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Tenda AC11 Router Stack Buffer Overflow Vulnerability

Schwachstelle

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 85.85% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
23.07.2026 17:03
https://github.com/Yu3H0/IoT_CVE/tree/main/Tenda/CVE_3
Third Party Advisory
Exploit
Broken Link
Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31755
US Government Resource