Vulnerability Description
Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac18 Firmware | 15.03.3.10_en |
| Tenda | Ac18 | - |
Related Weaknesses (CWE)
References
- https://palm-vertebra-fe9.notion.site/form_fast_setting_wifi_set-fd47294cf4bb460ExploitThird Party Advisory
- https://www.tendacn.com/hk/download/detail-3852.htmlBroken Link
- https://www.tendacn.com/hk/download/detail-3863.htmlBroken Link
FAQ
What is CVE-2024-41630?
CVE-2024-41630 is a vulnerability with a CVSS score of 7.6 (HIGH). Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.
How severe is CVE-2024-41630?
CVE-2024-41630 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41630?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac18 Firmware, Tenda Ac18.