CVE-2024-30891: Command Injection
Published Apr 5, 2024
·Updated
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
Affected Software
1 affected component
Tenda Ac18
Event History
Apr 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30891?
CVE-2024-30891 is classified as a high severity vulnerability due to its potential for arbitrary command execution.
2
How do I fix CVE-2024-30891?
To mitigate CVE-2024-30891, update the Tenda AC18 firmware to the latest version provided by Tenda.
3
What type of vulnerability is CVE-2024-30891?
CVE-2024-30891 is a command injection vulnerability that allows attackers to execute arbitrary commands.
4
Which devices are affected by CVE-2024-30891?
CVE-2024-30891 affects the Tenda AC18 router running firmware version v15.03.05.05.
5
What could an attacker do with CVE-2024-30891?
An attacker exploiting CVE-2024-30891 could potentially execute arbitrary commands on the affected Tenda AC18 device.