CVE-2024-51313
Tenda · TX9 router firmware
The Tenda TX9 router firmware version V22.03.02.20 contains a stack-based buffer overflow vulnerability in the /goform/SetVirtualServerCfg endpoint.
Executive summary
A critical stack overflow vulnerability in Tenda TX9 firmware allows unauthenticated remote attackers to execute arbitrary code or cause a denial-of-service condition.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring in the sub_42EA38 function when processing requests to the /goform/SetVirtualServerCfg endpoint. The vulnerability is exploitable by unauthenticated remote attackers who can submit crafted HTTP requests to trigger memory corruption.
Business impact
Successful exploitation of this vulnerability poses a severe risk to network infrastructure. Because the flaw allows for remote code execution, an attacker could gain full control over the router, facilitate lateral movement within the local network, or render the device inoperable. Given the CVSS score of 9.8, the potential for total system compromise is high, making immediate remediation essential to prevent unauthorized access or service disruption.
Remediation
Immediate Action: Update the Tenda TX9 router firmware to the latest available release provided by the vendor.
Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the /goform/SetVirtualServerCfg endpoint and review device access logs for signs of unauthorized configuration changes.
Compensating Controls: If an update cannot be applied immediately, restrict access to the router management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists in the research community.
Analyst recommendation
This vulnerability represents a critical risk to the integrity and availability of Tenda networking hardware. Administrators must prioritize the deployment of the latest firmware update to eliminate the buffer overflow condition. Failure to patch this device leaves the network perimeter exposed to potential remote code execution attacks.