First published: Tue Mar 26 2024(Updated: )
A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257940. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC7, AC9, and AC10 Routers | ||
All of | ||
Tenda AC7 | =15.03.06.44 | |
Tenda AC7, AC9, and AC10 Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2897 is classified as a critical severity vulnerability.
To fix CVE-2024-2897, it is recommended to update the Tenda AC7 firmware to a version that addresses this vulnerability.
CVE-2024-2897 is an OS command injection vulnerability affecting the Tenda AC7 device.
Yes, CVE-2024-2897 can be exploited remotely through the affected function.
The vulnerable function in CVE-2024-2897 is formWriteFacMac located in the /goform/WriteFacMac file.