First published: Wed Oct 23 2024(Updated: )
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Tenda AC15 Firmware | =15.03.05.18 | |
Tenda AC15 Firmware | =15.03.05.19 | |
Tenda AC15 | ||
All of | ||
Tenda AC7 Firmware | =15.03.06.44 | |
Tenda AC7V1.0 | ||
All of | ||
Any of | ||
Tenda AC10U Firmware | =15.03.06.48 | |
Tenda AC10U Firmware | =15.03.06.49 | |
Tenda AC10U firmware | ||
All of | ||
Any of | ||
Tenda AC500 firmware | =1.0.0.14 | |
Tenda AC500 firmware | =1.0.0.16 | |
Tenda AC500 firmware | =2.0.1.9\(1307\) | |
Tenda AC500 | ||
All of | ||
Any of | ||
Tenda AC18 firmware | =15.03.05.05 | |
Tenda AC18 firmware | =15.03.05.19\(6318\) | |
Tenda AC18 firmware | ||
All of | ||
Any of | ||
Tenda AC9 V1.0 Firmware | =15.03.2.13 | |
Tenda AC9 V1.0 Firmware | =15.03.05.14 | |
Tenda AC9 V1.0 Firmware | =15.03.05.19\(6318\) | |
Tenda AC9 V1.0 Firmware | =1.0 | |
All of | ||
Tenda AC9 V1.0 Firmware | =15.03.06.42 | |
Tenda AC9 V1.0 Firmware | =3.0 | |
All of | ||
Tenda AC1206 firmware | =15.03.06.23 | |
Tenda AC1206 firmware | ||
All of | ||
Tenda AC6 Firmware | =15.03.06.23 | |
Tenda AC6 firmware | =2.0 | |
All of | ||
Any of | ||
Tenda AC10V4 | =16.03.10.13 | |
Tenda AC10V4 | =16.03.10.20 | |
Tenda AC10V4 | =4.0 | |
All of | ||
Any of | ||
Tenda AC10V4 | =16.03.48.19 | |
Tenda AC10V4 | =16.03.48.23 | |
Tenda AC10V4 | =5.0 | |
All of | ||
Any of | ||
Tenda AC8 firmware | =16.03.34.06 | |
Tenda AC8 firmware | =16.03.34.09 | |
Tenda AC8 firmware | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10280 has been rated as a problematic vulnerability.
To fix CVE-2024-10280, update the affected Tenda firmware to the latest available version.
CVE-2024-10280 affects several Tenda devices including AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500, and AC1206 running specific firmware versions.
CVE-2024-10280 involves a manipulation of the Content-Length argument in the websReadEvent function related to the /goform/GetIPTV file.
CVE-2024-10280 was disclosed affecting Tenda devices up to the date of October 22, 2024.