Junglewise Threat Intelligence

CVE-2024-51314: Tenda TX9 Pro stack overflow in setMacFilterCfg

CVE-2024-51314 · Severity: info · Published 2026-07-20

Vendors: Tenda.

Executive brief

A security vulnerability exists in the Tenda TX9 Pro router, a device used to provide wireless internet access. An attacker can send a specially crafted web request to the router's management interface to cause a system crash or potentially take control of the device. This could lead to a complete loss of internet connectivity or unauthorized access to the network traffic passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the 'httpd' binary of Tenda TX9 Pro firmware version V22.03.02.20. The flaw is located in the 'sub_424CE0' function, which processes POST requests sent to the '/goform/setMacFilterCfg' endpoint. The function accepts a 'deviceList' parameter and passes it to 'sub_423B10', where an unsafe 'strcpy' operation occurs into a fixed-size stack buffer (v19). A remote attacker can exploit this by sending a long string in the 'deviceList' parameter, leading to memory corruption, denial of service, or potential remote code execution. No authentication requirements were specified in the advisory, though such endpoints typically require administrative access.

Affected products

  • Tenda TX9 Pro Firmware V22.03.02.20

Timeline

  • 2024-10-21: disclosed: Initial researcher write-up published on Gitee
  • 2026-07-20: advisory: CVE published to NVD

References