Junglewise Threat Intelligence

CVE-2024-51313: Tenda TX9 Pro stack overflow in SetNetControlList

CVE-2024-51313 · Severity: info · Published 2026-07-20

Technologies: Tenda TX9 Pro. Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda TX9 Pro router, a device used to provide wireless internet connectivity. An attacker can send a specially crafted web request to the router's management interface to cause a system crash or potentially take control of the device. This could lead to a complete loss of internet access for connected users or allow an attacker to intercept network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda TX9 Pro firmware version V22.03.02.20. The issue is located within the 'httpd' binary, specifically in the 'sub_4335DC' function (called by 'sub_4337EC' or 'sub_42EA38' depending on the specific firmware build) when processing the 'list' parameter via a POST request to '/goform/SetNetControlList' or '/goform/SetVirtualServerCfg'. The vulnerability is caused by an unsafe 'strcpy' operation that copies user-controlled input into a fixed-size stack buffer without length validation. A remote attacker can exploit this by sending a large payload in the 'list' parameter to overwrite the stack, potentially leading to arbitrary code execution or a Denial of Service (DoS).

Affected products

  • Tenda TX9 Pro V22.03.02.20

Timeline

  • 2024-10-21: disclosed: Initial researcher disclosure on Gitee
  • 2026-07-20: advisory: CVE published to NVD dataset

References

Related threats