CVE-2024-35339: Command Injection
Published May 24, 2024
·Updated
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
Affected Software
1 affected component
Tenda FH1206
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 24, 2024
CVE Published
via NVD·03:15 PM
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Aug 16, 2024
Data Sourced
via MITRE·06:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35339?
CVE-2024-35339 is classified as a critical vulnerability due to the potential for command injection.
2
How do I fix CVE-2024-35339?
To fix CVE-2024-35339, update the Tenda FH1206 firmware to the latest version provided by the vendor.
3
What systems are affected by CVE-2024-35339?
CVE-2024-35339 affects the Tenda FH1206 router running firmware version V1.2.0.8(8155).
4
What type of vulnerability is CVE-2024-35339?
CVE-2024-35339 is a command injection vulnerability that allows attackers to execute arbitrary commands.
5
What is the attack vector for CVE-2024-35339?
The attack vector for CVE-2024-35339 involves exploiting the mac parameter at the ip/goform/WriteFacMac endpoint.