CVE-2024-32317: High severity tenda ac7, ac9, and ac10 routers vulnerability
Published Apr 17, 2024
·Updated
Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
Affected Software
4 affected components
Tenda AC10>=V16.03.10.13<=V16.03.10.20
All of the following
Any of the following
Tenda Ac10 Firmware=16.03.10.13
Tenda Ac10 Firmware=16.03.10.20
Tenda AC10=4.0
Event History
Apr 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32317?
CVE-2024-32317 is classified as a high severity vulnerability due to the potential for remote code execution caused by a stack overflow.
2
How do I fix CVE-2024-32317?
To fix CVE-2024-32317, upgrade the firmware of Tenda AC10 to version V16.03.10.21 or later.
3
What products are affected by CVE-2024-32317?
CVE-2024-32317 affects Tenda AC10 devices running firmware versions V16.03.10.13 and V16.03.10.20.
4
What type of vulnerability is CVE-2024-32317?
CVE-2024-32317 is a stack overflow vulnerability that can be exploited via the adslPwd parameter in the formWanParameterSetting function.
5
Can CVE-2024-32317 be exploited remotely?
Yes, CVE-2024-32317 can be exploited remotely, making it critical to address this vulnerability promptly.