Junglewise Threat Intelligence

CVE-2024-51311: Tenda TX9 stack overflow in SetNetControlList

CVE-2024-51311 · Severity: info · CVSS 9.8 · Published 2026-07-20

Technologies: Tenda TX9 Pro. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in Tenda TX9 series routers, which are used to provide wireless internet connectivity. An attacker can exploit this flaw by sending a specially crafted web request to the router's management interface. If successful, this could allow the attacker to crash the device or potentially take full control of the router, compromising the security of the network and any data passing through it.

Technical details

A stack-based buffer overflow vulnerability exists in the 'httpd' binary of Tenda TX9/TX9 Pro firmware. The flaw is located in the 'sub_4335DC' function (called by 'sub_4337EC' or 'sub_4418CC' depending on firmware version) when processing the 'list' parameter via a POST request to the '/goform/SetNetControlList' endpoint. The application uses 'strcpy' to copy the user-controlled 'list' input into a fixed-size stack buffer without length validation. A remote, unauthenticated attacker can exploit this by sending a large payload to overwrite the return address, leading to a denial of service (system crash) or arbitrary code execution with root privileges.

Affected products

  • Tenda TX9 Pro V22.03.02.20
  • Tenda TX9 V22.03.02.05

Timeline

  • 2024-10-21: disclosed: Initial researcher disclosure with PoC
  • 2026-07-20: advisory: CVE published to NVD dataset

References

Related threats