CVE-2024-50854
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-50854 is a recently disclosed vulnerability affecting the Tenda G3 v3.0 v15.11.0.20 router firmware. This issue involves a stack overflow vulnerability, specifically in the formSetPortMapping function. An attacker could exploit this flaw by sending maliciously crafted requests to the router, potentially leading to the crash of the affected process and allowing for code injection or other types of attacks. Successful exploitation could result in unauthorized access to the router or the network it connects to, compromising user privacy and potentially leading to data theft or other malicious activities. Users are strongly encouraged to update their Tenda G3 routers to the latest firmware version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- G3