Sceawere
Vulnerability Detail
CVE-2026-104611UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tenda AC9 Stack-Based Buffer Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 10h ago
- Vendor
- Tenda
- Product
- AC9
- Attack Type
- Stack-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-02T13:17:44.640Z",
"pubdate": "2026-10-02T13:17:44.640Z",
"executiveSummary": "A critical stack-based buffer overflow vulnerability exists in Tenda AC9 firmware version 15.03.02.13.\nThe vulnerability resides within the POST request handler responsible for processing the '/goform/fast_setting_internet_set' URI.\nBy submitting a maliciously crafted 'netWanType' argument, an unauthenticated remote attacker can trigger memory corruption within the device's stack space.\nSuccessful exploitation allows for the execution of arbitrary code, potentially leading to a complete system compromise, unauthorized configuration changes, or denial-of-service conditions.\nGiven that the exploit vector is publicly available and network-accessible, the risk to affected devices is high, as the vulnerability does not require prior authentication or elevated privileges.",
"technicalDetails": "The vulnerability is a classic stack-based buffer overflow triggered during the handling of HTTP POST requests directed at the '/goform/fast_setting_internet_set' endpoint.\nThe root cause originates in the underlying binary component responsible for parsing the 'netWanType' parameter. It appears the application fails to perform adequate bounds checking on the user-supplied input before copying it into a fixed-size buffer allocated on the function's stack.\nWhen a POST request containing an excessively long 'netWanType' string is processed, the application performs a 'strcpy' or similar memory copy operation without validating the length of the source input against the destination buffer's capacity.\nThe overflow allows the attacker to overwrite critical data structures stored on the stack, including the saved return address (or stored frame pointer).\nBy carefully crafting the overflow payload, an attacker can hijack the instruction pointer (PC/EIP) when the function attempts to return, redirecting execution to attacker-controlled shellcode or triggering a Return-Oriented Programming (ROP) chain.\nBecause the service runs with elevated privileges and is exposed to the network, an attacker can conduct this exploit remotely without needing administrative credentials. The lack of stack canaries or similar stack-protection mechanisms in this version of the firmware facilitates the reliable redirection of execution flow.\nThe post-exploitation impact includes the potential for persistent backdoors, modification of device settings (such as DNS redirection or password resets), or the integration of the router into a botnet. Since the service is exposed via the router's web management interface, any device connected to the network—or potentially exposed to the internet if the web interface is misconfigured—serves as an attack vector."
}