Vulnerability Description
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-820Ap Firmware | 1.01.b01 |
| Trendnet | Tew-820Ap | - |
Related Weaknesses (CWE)
References
- https://github.com/ixout/iotVuls/blob/main/Trendnet/TEW_820/report.mdExploitThird Party Advisory
- https://www.trendnet.com/support/support-detail.asp?prod=100_TEW-820APBroken LinkVendor Advisory
FAQ
What is CVE-2024-50667?
CVE-2024-50667 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not s...
How severe is CVE-2024-50667?
CVE-2024-50667 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-50667?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-820Ap Firmware, Trendnet Tew-820Ap.