Executive brief
A security vulnerability exists in the Tenda TX9 Pro router, a device used to provide wireless internet connectivity. An attacker can send a specially crafted web request to the router's management interface to cause a system crash or potentially take control of the device. This could lead to a complete loss of internet access for connected users or allow an attacker to intercept network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda TX9 Pro firmware version V22.03.02.20. The issue is located within the 'httpd' binary, specifically in the 'sub_4335DC' function (called by 'sub_4337EC' or 'sub_42EA38' depending on the specific firmware build) when processing the 'list' parameter via a POST request to '/goform/SetNetControlList' or '/goform/SetVirtualServerCfg'. The vulnerability is caused by an unsafe 'strcpy' operation that copies user-controlled input into a fixed-size stack buffer without length validation. A remote attacker can exploit this by sending a large payload in the 'list' parameter to overwrite the stack, potentially leading to arbitrary code execution or a Denial of Service (DoS).
Affected products
- Tenda TX9 Pro V22.03.02.20
Timeline
- 2024-10-21: disclosed: Initial researcher disclosure on Gitee
- 2026-07-20: advisory: CVE published to NVD dataset