CVE-2024-2487
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-2487 is a newly disclosed critical vulnerability affecting the Tenda AC18 device with firmware version 15.03.05.05. This issue is related to the function formSetDeviceName in the file /goform/SetOnlineDevName, which is susceptible to a stack-based buffer overflow. The vulnerability can be triggered remotely by manipulating the argument devName/mac. The exploit for this vulnerability has been made public, increasing the risk for potential attacks. Vendors were contacted about this disclosure but did not respond, leaving users vulnerable until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.