CVE-2024-28545: Command Injection
Published Mar 26, 2024
·Updated
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.
Affected Software
3 affected components
Tenda Ac18
All of the following
Tenda Ac18 Firmware=15.03.05.05
Tenda Ac18
Event History
Mar 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28545?
CVE-2024-28545 has been classified with a high severity due to its potential for command injection.
2
How do I fix CVE-2024-28545?
To fix CVE-2024-28545, update the Tenda AC18 firmware to the latest version provided by the vendor.
3
What is the specific vulnerability in CVE-2024-28545?
CVE-2024-28545 involves a command injection vulnerability in the deviceName parameter of the setUsbUnload function.
4
Which devices are affected by CVE-2024-28545?
CVE-2024-28545 specifically affects the Tenda AC18 router running firmware version V15.03.05.05.
5
What are the potential risks of CVE-2024-28545?
The potential risks of CVE-2024-28545 include unauthorized command execution on the affected device, which can compromise its security.