CVE-2024-2487

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 15, 2024
Updated: Jan 14, 2025
CWE ID 352

Summary

CVE-2024-2487 is a newly disclosed critical vulnerability affecting the Tenda AC18 device with firmware version 15.03.05.05. This issue is related to the function formSetDeviceName in the file /goform/SetOnlineDevName, which is susceptible to a stack-based buffer overflow. The vulnerability can be triggered remotely by manipulating the argument devName/mac. The exploit for this vulnerability has been made public, increasing the risk for potential attacks. Vendors were contacted about this disclosure but did not respond, leaving users vulnerable until a patch is released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share