CVE-2024-3009: Tenda FH1205 WriteFacMac formWriteFacMac command injection
A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258295. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3009?
CVE-2024-3009 is classified as a critical vulnerability.
How do I fix CVE-2024-3009?
To mitigate CVE-2024-3009, it is recommended to update the Tenda FH1205 firmware to a version that addresses this vulnerability.
What type of vulnerability is CVE-2024-3009?
CVE-2024-3009 is a command injection vulnerability exploited through the formWriteFacMac function.
Can CVE-2024-3009 be exploited remotely?
Yes, CVE-2024-3009 can be exploited remotely, allowing attackers to execute commands on the affected device.
What devices are affected by CVE-2024-3009?
CVE-2024-3009 affects the Tenda FH1205 firmware version 2.0.0.7(775).