First published: Tue May 14 2024(Updated: )
Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC18 firmware | ||
All of | ||
Tenda AC18 Firmware | =15.03.05.19 | |
Tenda AC18 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34974 is classified as a critical severity vulnerability due to the potential for remote code execution.
To fix CVE-2024-34974, update the Tenda AC18 firmware to the latest version provided by the manufacturer.
The CVE-2024-34974 vulnerability is caused by a buffer overflow in the formSetPPTPServer function that improperly handles user input in the endIp parameter.
CVE-2024-34974 specifically affects the Tenda AC18 router firmware version 15.03.05.19.
Yes, CVE-2024-34974 can be exploited remotely by an attacker sending crafted requests to the vulnerable device.