CVE-2024-2899

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 26, 2024
Updated: May 17, 2024
CWE ID 22

Summary

CVE-2024-2899 is a newly disclosed critical vulnerability affecting the Tenda AC7 model with firmware version 15.03.06.44. This issue lies in the fromSetWirelessRepeat function of the WifiExtraSet file. When the wpapsk\_crypto argument is manipulated, it results in a stack-based buffer overflow. An attacker can exploit this remotely, making it a significant threat. Despite early notification, the vendor has yet to respond, leaving users vulnerable to the exploit, which has already been made public (VDB-257942).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share