CVE-2024-51313
A critical stack overflow flaw exists in the Tenda TX9 router firmware version V22.03.02.20. The bug is triggered by the /goform/SetVirtualServerCfg function and could let an attacker crash or take control of the device.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
The flaw affects the Tenda TX9 router model running firmware version V22.03.02.20. Users of this specific firmware are at risk.
Real-world impact
An attacker could exploit the stack overflow to crash the router or execute arbitrary code, potentially taking control of the device and compromising network traffic.
Why this severity
The CVSS score of 9.8 reflects the vulnerability’s high impact: it can be triggered remotely without authentication, with no user interaction, and can lead to full compromise of confidentiality, integrity, and availability.
What to do about it
- ›Avoid using the affected firmware version; if possible, disable the /goform/SetVirtualServerCfg feature or the virtual server functionality.
- ›Monitor the vendor for firmware updates that address the issue.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources.