{"gsd":{"metadata":{"exploitCode":"unknown","remediation":"unknown","reportConfidence":"confirmed","type":"vulnerability"},"osvSchema":{"aliases":["CVE-2024-4291"],"details":"A vulnerability was found in Tenda A301 15.13.08.12_multi_TDE01. It has been rated as critical. This issue affects the function formAddMacfilterRule of the file /goform/setBlackRule. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-262223. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.","id":"GSD-2024-4291","modified":"2024-04-28T05:02:06.058388Z","schema_version":"1.4.0"}},"namespaces":{"cve.org":{"CVE_data_meta":{"ASSIGNER":"cna@vuldb.com","ID":"CVE-2024-4291","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"A301","version":{"version_data":[{"version_affected":"=","version_value":"15.13.08.12_multi_TDE01"}]}}]},"vendor_name":"Tenda"}]}},"credits":[{"lang":"en","value":"L1ziang (VulDB User)"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability was found in Tenda A301 15.13.08.12_multi_TDE01. It has been rated as critical. This issue affects the function formAddMacfilterRule of the file /goform/setBlackRule. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-262223. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"deu","value":"Eine Schwachstelle wurde in Tenda A301 15.13.08.12_multi_TDE01 ausgemacht. Sie wurde als kritisch eingestuft. Betroffen davon ist die Funktion formAddMacfilterRule der Datei /goform/setBlackRule. Mittels dem Manipulieren des Arguments deviceList mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}]},"impact":{"cvss":[{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.0"},{"baseScore":9,"vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","version":"2.0"}]},"problemtype":{"problemtype_data":[{"description":[{"cweId":"CWE-121","lang":"eng","value":"CWE-121 Stack-based Buffer Overflow"}]}]},"references":{"reference_data":[{"name":"https://vuldb.com/?id.262223","refsource":"MISC","url":"https://vuldb.com/?id.262223"},{"name":"https://vuldb.com/?ctiid.262223","refsource":"MISC","url":"https://vuldb.com/?ctiid.262223"},{"name":"https://vuldb.com/?submit.320672","refsource":"MISC","url":"https://vuldb.com/?submit.320672"},{"name":"https://github.com/L1ziang/Vulnerability/blob/main/formAddMacfilterRule.md","refsource":"MISC","url":"https://github.com/L1ziang/Vulnerability/blob/main/formAddMacfilterRule.md"}]}},"nvd.nist.gov":{"cve":{"descriptions":[{"lang":"en","value":"A vulnerability was found in Tenda A301 15.13.08.12_multi_TDE01. It has been rated as critical. This issue affects the function formAddMacfilterRule of the file /goform/setBlackRule. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-262223. NOTE: The vendor was contacted early about this disclosure but did not respond in any way."}],"id":"CVE-2024-4291","lastModified":"2024-04-27T20:15:07.170","metrics":{"cvssMetricV2":[{"acInsufInfo":false,"baseSeverity":"HIGH","cvssData":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"SINGLE","availabilityImpact":"COMPLETE","baseScore":9.0,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","version":"2.0"},"exploitabilityScore":8.0,"impactScore":10.0,"obtainAllPrivilege":false,"obtainOtherPrivilege":false,"obtainUserPrivilege":false,"source":"cna@vuldb.com","type":"Secondary","userInteractionRequired":false}],"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"exploitabilityScore":2.8,"impactScore":5.9,"source":"cna@vuldb.com","type":"Secondary"}]},"published":"2024-04-27T20:15:07.170","references":[{"source":"cna@vuldb.com","url":"https://github.com/L1ziang/Vulnerability/blob/main/formAddMacfilterRule.md"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?ctiid.262223"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?id.262223"},{"source":"cna@vuldb.com","url":"https://vuldb.com/?submit.320672"}],"sourceIdentifier":"cna@vuldb.com","vulnStatus":"Received","weaknesses":[{"description":[{"lang":"en","value":"CWE-121"}],"source":"cna@vuldb.com","type":"Primary"}]}}}}