CVE-2024-28550: Medium severity tenda ac18 firmware vulnerability
Published Mar 18, 2024
·Updated
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
Affected Software
3 affected components
Tenda Ac18
All of the following
Tenda Ac18 Firmware=15.03.05.05
Tenda Ac18
Event History
Mar 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28550?
CVE-2024-28550 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2024-28550?
To fix CVE-2024-28550, update the Tenda AC18 firmware to the latest version provided by the manufacturer.
3
What is the impact of CVE-2024-28550 on Tenda AC18?
CVE-2024-28550 allows an attacker to exploit a stack overflow vulnerability, potentially leading to unauthorized access or control over the device.
4
Which versions of Tenda AC18 are affected by CVE-2024-28550?
CVE-2024-28550 affects Tenda AC18 firmware versions prior to V15.03.05.05.
5
What is the nature of the vulnerability in CVE-2024-28550?
CVE-2024-28550 is a stack overflow vulnerability found specifically in the filePath parameter of the formExpandDlnaFile function.