CVE-2024-35340: Command Injection
Published May 24, 2024
·Updated
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.
Affected Software
1 affected component
Tenda FH1206
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 24, 2024
CVE Published
via NVD·03:15 PM
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Aug 10, 2024
Data Sourced
via MITRE·04:21 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35340?
CVE-2024-35340 has a high severity rating due to its potential to allow remote code execution via command injection.
2
How do I fix CVE-2024-35340?
To fix CVE-2024-35340, update the Tenda FH1206 to the latest firmware version that addresses this vulnerability.
3
What products are affected by CVE-2024-35340?
CVE-2024-35340 affects the Tenda FH1206 router running firmware version V1.2.0.8(8155).
4
What is the nature of the vulnerability in CVE-2024-35340?
CVE-2024-35340 is a command injection vulnerability that can be exploited via the cmdinput parameter at ip/goform/formexeCommand.
5
Who can be impacted by CVE-2024-35340?
Users of the Tenda FH1206 router with the vulnerable firmware version may be impacted by CVE-2024-35340.