CVE-2024-46431

CVSS 3.1 Score 8 of 10 (high)

Details

Published Feb 10, 2025
CWE ID 120

Summary

CVE-2024-46431 is a newly identified buffer overflow vulnerability affecting Tenda W18E V16.01.0.8(1625) firmware. This issue arises due to a flaw in the delWewifiPic function, which can be exploited by attackers with access to the web management portal. They can send specially crafted data to induce a buffer overflow, potentially leading to unintended system behavior or code execution. Successful exploitation may result in unauthorized access, data theft, or other malicious activities. Users are encouraged to update their firmware as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share