CVE-2024-7585
CVSS 2.0 Score 9.0 of 10 (high)
Details
Published Aug 7, 2024
CWE ID 120
Summary
CVE-2024-7585 is a newly disclosed critical vulnerability that affects the Tenda i22 firmware version 1.0.0.3(4687). This issue lies within the function formApPortalWebAuth in the /goform/apPortalAuth file. An attacker can exploit this buffer overflow vulnerability by manipulating the webUserName/webUserPassword arguments, allowing remote code execution. The vendor was notified about this disclosure but did not respond. Public exploits for this vulnerability are now available, making it a serious threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Tenda i22
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd