Junglewise Threat Intelligence

CVE-2021-31755: Tenda AC11 Router Stack Buffer Overflow Vulnerability

CVE-2021-31755 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Tenda.

Executive brief

Tenda AC11 router devices are vulnerable to a stack-based buffer overflow in the /goform/setmac endpoint. An attacker can exploit this by sending a specially crafted POST request to execute arbitrary code on the system.

Affected products

  • Tenda AC11 through 02.03.01.104_CN

Timeline

  • 2021-05-07: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-17: other: CISA KEV due date for remediation