Skip to content

Latest commit

 

History

History
21 lines (11 loc) · 1.01 KB

sub_4260F0.md

File metadata and controls

21 lines (11 loc) · 1.01 KB

Overview

Affected version

4G300 V1.01.42

Vulnerability details

The Tenda 4G300 V1.01.42 firmware has a stack overflow vulnerability in the sub_4260F0 function. The v2 variable receives the upfilen parameter from a POST request. However, since the user can control the input of upfilen , the statement can cause a buffer overflow. The user-provided upfilen can exceed the capacity of the v20 array, triggering this security vulnerability.

image-20240418110146541

image-20240418110137067

image-20240418110201845

POC

image-20240416114043980