Description
A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysToolChangePwd. Such manipulation of the argument oldPwd/newPwd/cfmPwd leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-04-08: | Advisory disclosed |
| 2026-04-08: | VulDB entry created |
| 2026-04-08: | VulDB entry last update |
Credits
meshaal (VulDB User)
References
vuldb.com/vuln/356277 (VDB-356277 | Tenda AC15 SysToolChangePwd websGetVar stack-based overflow)
vuldb.com/vuln/356277/cti (VDB-356277 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/789178 (Submit #789178 | Tenda AC15 15.03.05.18 Memory Corruption)
files.catbox.moe/xrk8jb.zip
www.tenda.com.cn/