CVE-2024-51315
Tenda · TX9
The Tenda TX9 router firmware version V22.03.02.20 contains a stack overflow vulnerability in the /goform/SetOnlineDevName endpoint that may result in arbitrary code execution.
Executive summary
A critical stack overflow vulnerability in Tenda TX9 firmware allows unauthenticated attackers to execute malicious code or disrupt device operations.
Vulnerability
This is a stack overflow vulnerability within the sub_425964 function of the /goform/SetOnlineDevName file. Unauthenticated attackers can exploit this flaw by sending specifically crafted inputs to the target endpoint, leading to memory corruption and potential arbitrary code execution.
Business impact
With a CVSS score of 9.8, this vulnerability represents a severe threat to infrastructure integrity. An attacker who successfully exploits this flaw can achieve unauthorized administrative access, compromise sensitive network information, or render the device unusable, leading to significant business downtime.
Remediation
Immediate Action: Verify the availability of firmware updates via the Tenda support portal and perform an immediate upgrade to the latest secure version.
Proactive Monitoring: Implement monitoring to detect unusual activity or repeated crashes associated with the /goform/SetOnlineDevName endpoint in network device logs.
Compensating Controls: Utilize a Web Application Firewall or similar security appliance to block malformed HTTP requests that target known administrative interfaces on the router.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept is available via external research repositories.
Analyst recommendation
The critical nature of this flaw necessitates immediate attention. Organizations utilizing Tenda TX9 hardware must track official vendor communications for patch availability and ensure that any exposed devices are shielded from public-facing network segments until remediation is complete.