← Vulnerability feed

Vulnerability record · CVE-2021-27707 · published 14 April 2021

CVE-2021-27707: Tenda g1 firmware classic buffer overflow vulnerability

Tenda · G1 Firmware

Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.

9.8 CVSS 3.1 Critical EPSS 2.8% · top 13.9% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://hackmd.io/U7OVgYIuRcOKV7SW5-euHw ExploitThird Party Advisory
https://hackmd.io/U7OVgYIuRcOKV7SW5-euHw ExploitThird Party Advisory

Track CVE-2021-27707 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4165Tenda g3 firmware stack-based buffer overflow vulnerabilityA vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.17(9502). Affected is the function modifyDhcpRule of the file /gofor…EPSS 1.5%9.8CVE-2024-4164Tenda g3 firmware stack-based buffer overflow vulnerabilityA vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.17(9502). This issue affects the function formModifyPppAuthWhit…EPSS 1.5%9.8CVE-2022-36586Tenda g3 firmware classic buffer overflow vulnerabilityIn Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.EPSS 0.94%9.8CVE-2022-36585Tenda g3 firmware classic buffer overflow vulnerabilityIn Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.EPSS 0.94%9.8CVE-2022-36587Tenda g3 firmware classic buffer overflow vulnerabilityIn Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.EPSS 0.94%9.8CVE-2022-36584Tenda g3 firmware classic buffer overflow vulnerabilityIn Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.EPSS 0.94%9.8CVE-2021-27706Tenda g1 firmware classic buffer overflow vulnerabilityBuffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted…EPSS 2.8%9.8CVE-2021-27705Tenda g1 firmware classic buffer overflow vulnerabilityBuffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2021-27707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.