FAIL › dossier
i29 firmware
PRODUCT· dossier confidence 20%
Tenda's i29 firmware suffered a catastrophic security failure in late 2023, with nine critical vulnerabilities (RCEs, buffer overflows, stack overflows) discovered simultaneously. The pattern of unvalidated inputs across multiple system functions suggests a deep-seated lack of secure coding practices in their firmware development lifecycle.
Tenda's firmware for the i29 device exhibited a severe lack of input validation and memory safety, resulting in nine critical vulnerabilities (CVE-2023-50983 through CVE-2023-50992) all discovered and disclosed on the same day in December 2023. The vulnerabilities span command injection, buffer overflows, and stack overflows across multiple system functions, indicating a systemic failure in secure coding practices and a reactive rather than proactive security posture.
- CVE-2023-50983: Command injection via sysScheduleRebootSet
- CVE-2023-50989: Command injection via pingSet
- CVE-2023-50985: Buffer overflow via lanGw parameter
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-12-20 | CVE-2023-50983 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function. |
| 2023-12-20 | CVE-2023-50989 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function. |
| 2023-12-20 | CVE-2023-50985 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function. |
| 2023-12-20 | CVE-2023-50986 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function. |
| 2023-12-20 | CVE-2023-50988 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function. |
| 2023-12-20 | CVE-2023-50990 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function. |
| 2023-12-20 | CVE-2023-50987 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function. |
| 2023-12-20 | CVE-2023-50992 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function. |
| 2023-12-20 | CVE-2023-50984 | critical | Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function. |
- Material Center - Tenda Global · www.tendacn.com
- 下载中心 - 腾达 (Tenda) 官方网站 · www.tenda.com.cn
- Tenda CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io