Executive brief
A vulnerability exists in the Tenda AC8V4 home router, a device used to provide wireless internet connectivity. An attacker can send a specially crafted request to the router's time configuration settings to cause the device to crash or become unresponsive. This could disrupt internet access for all connected users and require a manual restart of the hardware.
Technical details
A stack-based buffer overflow (CWE-121) exists in the 'fromSetSysTime' function of the Tenda AC8V4 router firmware. When the 'timeType' parameter is set to 'sync', the application calls a sub-function (at address 004A75C0) that processes the 'timeZone' parameter. This parameter is retrieved from a POST request without length validation and is subsequently passed to a 'strcpy' call, leading to a stack overflow. A remote, unauthenticated attacker can exploit this by sending a long string in the 'timeZone' field to cause a denial-of-service (DoS) condition. Proof-of-concept code demonstrates the crash using a 2000-byte payload.
Affected products
- Tenda AC8V4 V16.03.34.06
Timeline
- 2025-07-24: disclosed: Initial vulnerability disclosure
- 2025-07-24: advisory: NVD publication date