CVE-2024-2489

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 15, 2024
Updated: Jan 14, 2025
CWE ID 78
CWE ID 269

Summary

CVE-2024-2489 is a newly disclosed critical vulnerability affecting Tenda AC18 routers running firmware version 15.03.05.05. This issue lies in the formSetQosBand function of the SetNetControlList file, where a stack-based buffer overflow can be triggered through manipulation of the argument list. An attacker can exploit this remotely, making it a serious concern. The vulnerability identifier is VDB-256896, and the exploit has already been made public. Regrettably, the vendor did not respond to early disclosure attempts, leaving affected users at potential risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share