← Vulnerability feed

Vulnerability record · CVE-2024-4112 · published 24 April 2024

CVE-2024-4112: Tenda tx9 pro firmware stack-based buffer overflow vulnerability

Tenda · Tx9 Pro Firmware

A vulnerability classified as critical has been found in Tenda TX9 22.03.02.10. This affects the function sub_42CB94 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

8.8 CVSS 3.1 High EPSS 1.7% · top 23.7% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 9.0
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as critical has been found in Tenda TX9 22.03.02.10. This affects the function sub_42CB94 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261855. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/TX9/formSetVirtualSer.md Broken Link
https://vuldb.com/?ctiid.261855 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.261855 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.317206 Third Party AdvisoryVDB Entry
https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/TX9/formSetVirtualSer.md Broken Link
https://vuldb.com/?ctiid.261855 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.261855 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.317206 Third Party AdvisoryVDB Entry

Track CVE-2024-4112 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-29591Tenda tx9 pro firmware classic buffer overflow vulnerabilityTenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.EPSS 1.4%9.8CVE-2022-29592Tenda tx9 pro firmware os command injection vulnerabilityTenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).EPSS 20%8.8CVE-2024-4114Tenda tx9 pro firmware stack-based buffer overflow vulnerabilityA vulnerability, which was classified as critical, has been found in Tenda TX9 22.03.02.10. This issue affects the function sub_42C014 of the file /g…EPSS 1.3%8.8CVE-2024-4113Tenda tx9 pro firmware stack-based buffer overflow vulnerabilityA vulnerability classified as critical was found in Tenda TX9 22.03.02.10. This vulnerability affects the function sub_42D4DC of the file /goform/Set…EPSS 1.5%8.8CVE-2024-4111Tenda tx9 pro firmware stack-based buffer overflow vulnerabilityA vulnerability was found in Tenda TX9 22.03.02.10. It has been rated as critical. Affected by this issue is the function sub_42BD7C of the file /gof…EPSS 1.5%7.8CVE-2022-38510Tenda tx9 pro firmware classic buffer overflow vulnerabilityTenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.EPSS 0.33%7.5CVE-2022-45337Tenda tx9 pro firmware out-of-bounds write vulnerabilityTenda TX9 Pro v22.03.02.10 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.EPSS 0.82%7.5CVE-2022-30033Tenda tx9 pro firmware classic buffer overflow vulnerabilityTenda TX9 Pro V22.03.02.10 is vulnerable to Buffer Overflow via the functtion setIPv6Status() in httpd module.EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2024-4112), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.