CVE-2024-34338: Command Injection
Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTraceroute. This vulnerability allows attackers to execute arbitrary commands with root privileges. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34338?
CVE-2024-34338 is classified as a high severity vulnerability due to its potential for remote command execution with root privileges.
How do I fix CVE-2024-34338?
To fix CVE-2024-34338, update the Tenda O3V2 firmware to the latest version that addresses this vulnerability.
What versions of Tenda O3V2 are affected by CVE-2024-34338?
Tenda O3V2 firmware versions V1.0.0.10 and V1.0.0.12 are affected by CVE-2024-34338.
Can CVE-2024-34338 be exploited without authentication?
No, CVE-2024-34338 requires authentication in order to exploit the blind command injection vulnerability.
What kind of impact can CVE-2024-34338 have on my device?
CVE-2024-34338 can allow an attacker to execute arbitrary commands on the Tenda O3V2 device, potentially compromising its security.