Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://cwe.mitre.org/data/definitions/121.html | technical description |
https://github.com/1sd3d/Tendown/tree/master/PoCs/Auth/bof11 | broken link |
https://github.com/Lyc-heng/routers/blob/main/routers/stack1.md | third party advisory exploit |