CVE-2024-50667
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 120
Summary
CVE-2024-50667 is a stack overflow vulnerability affecting the boa httpd service in Trendnet TEW-820AP 1.01.B01 routers. The issue lies in the handling of IPv6 addresses in the /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, and /boafrm/formDnsv6 pages. An attacker can exploit this vulnerability by constructing specially crafted payloads that trigger a stack overflow, potentially leading to remote code execution or denial of service. The root cause is inadequate validation of IPv6 addresses during user input processing.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.