CVE-2024-57580
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-57580 is a newly discovered stack overflow vulnerability affecting Tenda AC18 routers running V15.03.05.19 firmware. The issue resides in the formSetDeviceName function, which processes the devName parameter. A maliciously crafted devName input can cause the function to exceed the stack limit, potentially leading to buffer overflow and subsequent code execution. This poses a serious threat to users as an attacker can exploit this vulnerability to gain unauthorized access or even take control of the affected device. It is strongly recommended that users update their firmware to a non-vulnerable version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.