Skip to content

Latest commit

 

History

History
19 lines (10 loc) · 894 Bytes

sub_429A30.md

File metadata and controls

19 lines (10 loc) · 894 Bytes

Overview

Affected version

4G300 V1.01.42

Vulnerability details

The Tenda 4G300 V1.01.42 firmware has a stack overflow vulnerability in the sub_429A30 function. The v4 variable receives the list1 parameter from a POST request. However, since the user can control the input of list1 , the statement can cause a buffer overflow. The user-provided list1 can exceed the capacity of the v15 array, triggering this security vulnerability.

image-20240418110652578

image-20240418110642632

POC

image-20240416114043980