CVE-2024-4123

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 24, 2024
CWE ID 121

Summary

A critical vulnerability, identified as CVE-2024-4123, has been discovered in Tenda W15E version 15.11.0.14. The vulnerability exists in the function formSetPortMapping of the file /goform/SetPortMapping and can be exploited through remote attacks. By manipulating certain arguments, such as portMappingServer and portMappingProtocol, a stack-based buffer overflow can occur. The exploit has been publicly disclosed and is potentially dangerous for organizations using the affected product. Despite being informed about the disclosure, the vendor did not respond. The vulnerability has a high base severity score of 8.8 and poses risks to confidentiality and integrity with an impact score of 5.9 out of 10 according to CVSS:3.1 metrics.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-4123 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options