CVE-2024-10750: Tenda i22 SysToo websReadEvent null pointer dereference
A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10750?
CVE-2024-10750 has been classified as a problematic vulnerability due to the potential for null pointer dereference.
How do I fix CVE-2024-10750?
To mitigate CVE-2024-10750, ensure that the Tenda i22 firmware is updated to the latest version.
Which devices are affected by CVE-2024-10750?
CVE-2024-10750 affects the Tenda i22 device running firmware version 1.0.0.3(4687).
What is the impact of CVE-2024-10750 on my device?
The impact of CVE-2024-10750 could lead to instability and possible denial of service due to null pointer dereference.
How was CVE-2024-10750 discovered?
CVE-2024-10750 was discovered through security analysis of the websReadEvent function in the affected firmware.