CVE-2024-51314
Deferred Deferred - Pending Action

Stack Overflow in Tenda TX9 V22.03.02.20 Firmware

Vulnerability report for CVE-2024-51314, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-21

Assigner: MITRE

Description

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-21
Generated
2026-08-10
AI Q&A
2026-07-21
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tenda tx9 22.03.02.20

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Tenda TX9 V22.03.02.20 firmware contains a stack overflow vulnerability in the sub_424CE0 function within the /goform/setMacFilterCfg file. This flaw allows attackers to overwrite critical memory regions by sending maliciously crafted input.

Detection Guidance

To detect this vulnerability, check if your Tenda TX9 router is running firmware version V22.03.02.20. You can do this by accessing the router's admin panel or using network scanning tools to identify the firmware version. Additionally, monitor network traffic for POST requests to the /goform/setMacFilterCfg endpoint with unusually long deviceList parameters.

Impact Analysis

An attacker could exploit this to execute arbitrary code on the device, potentially gaining control over the router. This may lead to network compromise, unauthorized access, or disruption of network services.

Compliance Impact

This vulnerability could lead to unauthorized access or control of the Tenda TX9 router, potentially compromising network security. For GDPR, it may result in unauthorized data access or processing, violating confidentiality requirements. For HIPAA, it could expose protected health information if the device is used in healthcare environments. The lack of input validation in the deviceList parameter directly conflicts with security controls required by these standards.

Mitigation Strategies

Update the Tenda TX9 V22.03.02.20 firmware to the latest version to address the stack overflow vulnerability in the sub_424CE0 function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-51314. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart