Vulnerability Details CVE-2020-20746
A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 85.6%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2020-20746
-
cpe:2.3:h:tendacn:ac9:3.0
-
cpe:2.3:o:tendacn:ac9_firmware:15.03.06.60_en