CVE-2024-51312
Tenda · TX9
A stack overflow vulnerability in the Tenda TX9 firmware allows for potential remote code execution via the /goform/SetStaticRouteCfg interface.
Executive summary
A critical stack overflow vulnerability in Tenda TX9 firmware enables unauthenticated remote code execution, posing a significant risk of total device compromise.
Vulnerability
The vulnerability exists in the sub_42EEE0 function within the /goform/SetStaticRouteCfg endpoint. An unauthenticated attacker can send a crafted request that triggers a stack overflow, potentially leading to arbitrary code execution.
Business impact
With a CVSS score of 9.8, this vulnerability represents a critical threat to network integrity. An attacker who gains control of a Tenda router can intercept traffic, redirect users to malicious sites, or use the device as a persistent foothold within the local network to attack other connected systems.
Remediation
Immediate Action: Check the Tenda support website for firmware updates addressing this stack overflow issue.
Proactive Monitoring: Monitor router logs for abnormal activity related to the /goform/SetStaticRouteCfg endpoint and unusual traffic patterns.
Compensating Controls: Disable remote administrative access to the router interface and ensure that the management interface is not accessible from the public internet.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists.
Analyst recommendation
The critical nature of this vulnerability requires immediate attention. Organizations should verify their firmware version and apply any available security patches from Tenda to prevent potential remote code execution. If a patch is not yet available, restrict management access to the device to trusted local subnets only.