CVE-2024-50852

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 13, 2024
Updated: Nov 14, 2024
CWE ID 77

Summary

CVE-2024-50852 is a newly disclosed vulnerability affecting the Tenda G3 v3.0 v15.11.0.20 firmware. The issue involves a command injection flaw in the formSetUSBPartitionUmount function. An attacker can exploit this vulnerability by sending maliciously crafted input to the function, potentially executing arbitrary commands with root privileges on the affected device. Successful exploitation of this vulnerability could lead to unauthorized access, data theft, or system compromise. Users are strongly advised to update their firmware as soon as a patch becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share