CVE-2024-2488 | Tenda AC18 15.03.05.05 /goform/SetPptpServerCfg formSetPPTPServer startIP stack-based overflow
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIP leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-2488. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.