CVE-2024-46431

Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function.
References
Link Resource
https://reddassolutions.com/blog/tenda_w18e_security_research Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*

History

25 Mar 2025, 18:12

Type Values Removed Values Added
First Time Tenda w18e Firmware
Tenda w18e
Tenda
Summary
  • (es) Tenda W18E V16.01.0.8(1625) es vulnerable a desbordamiento de búfer. Un atacante con acceso al portal de administración web puede aprovechar esta vulnerabilidad enviando datos especialmente manipulados a la función delWewifiPic.
References () https://reddassolutions.com/blog/tenda_w18e_security_research - () https://reddassolutions.com/blog/tenda_w18e_security_research - Exploit, Third Party Advisory
CPE cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*

10 Feb 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : 8.0

10 Feb 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-120

10 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-10 19:15

Updated : 2025-03-25 18:12


NVD link : CVE-2024-46431

Mitre link : CVE-2024-46431

CVE.ORG link : CVE-2024-46431


JSON object : View

Products Affected

tenda

  • w18e_firmware
  • w18e
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')