CVE-2024-51316

Tenda · TX9

The Tenda TX9 router firmware version V22.03.02.20 contains a denial of service vulnerability in the update_dev_name function, allowing remote attackers to crash the device.

Executive summary

A high-severity denial of service vulnerability in Tenda TX9 firmware allows unauthenticated attackers to crash the device and disrupt network connectivity.

Vulnerability

The vulnerability is located in the update_dev_name function within the /goform/SetOnlineDevName file. It permits an unauthenticated attacker to cause a denial of service by sending crafted requests that trigger a crash in the affected software component.

Business impact

This vulnerability has a CVSS score of 7.5, reflecting a significant impact on service availability. A successful attack can force the router to become unresponsive, effectively cutting off network access for all connected users and systems, which may result in operational disruption and loss of productivity.

Remediation

Immediate Action: Check the Tenda support website regularly for firmware updates and apply them as soon as a fix is released for the TX9.

Proactive Monitoring: Monitor device uptime and connectivity logs to identify sudden, unexplained service interruptions that may indicate an ongoing denial of service attempt.

Compensating Controls: Restrict access to the router's web management interface to trusted IP addresses only, reducing the attack surface available to potential remote adversaries.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept is available via external research repositories.

Analyst recommendation

While less severe than code execution vulnerabilities, the potential for sustained denial of service warrants prompt action. Administrators should treat this vulnerability as a high priority for remediation once the vendor provides a patch and consider network segmentation as a temporary measure to limit exposure.