CVE-2024-46431

Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function.
References
Link Resource
https://reddassolutions.com/blog/tenda_w18e_security_research Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*

History

25 Mar 2025, 18:12

Type Values Removed Values Added
Summary
  • (es) Tenda W18E V16.01.0.8(1625) es vulnerable a desbordamiento de búfer. Un atacante con acceso al portal de administración web puede aprovechar esta vulnerabilidad enviando datos especialmente manipulados a la función delWewifiPic.
CPE cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
References () https://reddassolutions.com/blog/tenda_w18e_security_research - () https://reddassolutions.com/blog/tenda_w18e_security_research - Exploit, Third Party Advisory
First Time Tenda w18e Firmware
Tenda
Tenda w18e

10 Feb 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : 8.0

10 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

10 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-10 19:15

Updated : 2025-03-25 18:12


NVD link : CVE-2024-46431

Mitre link : CVE-2024-46431

CVE.ORG link : CVE-2024-46431


JSON object : View

Products Affected

tenda

  • w18e_firmware
  • w18e
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')