CVE-2021-31755
Published · Updated
95Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 9.8epss 87%
from disclosure to weapon
Published on NVDMay 7
CISA KEV+180d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2021-11-17
Apply updates per vendor instructions.
In short
A vulnerability in Tenda AC11 routers allows attackers to send a specially crafted request that overwrites memory on the device, letting them run malicious code with full control of the router.
Technical detail
Stack buffer overflow in the /goform/setmac endpoint (CWE-787) allows unauthenticated remote code execution via POST request with oversized input. The vulnerability affects Tenda AC11 firmware versions up to 02.03.01.104_CN, enabling arbitrary code execution with device-level privileges.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a