First published: Fri Mar 29 2024(Updated: )
Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC15 | ||
All of | ||
Tenda A15 | =15.03.20_multi | |
Tenda AC15 | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30645 is classified as a high-severity command injection vulnerability.
To mitigate CVE-2024-30645, it is recommended to upgrade the Tenda AC15 firmware to the latest available version.
CVE-2024-30645 is caused by improper input validation on the deviceName parameter.
CVE-2024-30645 affects the Tenda AC15 devices running firmware version 15.03.20_multi.
Yes, CVE-2024-30645 can be exploited remotely by an attacker with access to the network.