CVE-2024-35578: High severity tenda ax1806 firmware vulnerability
Published May 20, 2024
·Updated
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
Affected Software
3 affected components
Tenda AX1806
All of the following
Tenda Ax1806 Firmware=1.0.0.1
Tenda AX1806
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 20, 2024
CVE Published
via NVD·06:15 PM
Aug 3, 2024
Data Sourced
via MITRE·04:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35578?
CVE-2024-35578 is classified as a critical vulnerability due to its potential for remote code execution via stack overflow.
2
How do I fix CVE-2024-35578?
To fix CVE-2024-35578, update the Tenda AX1806 firmware to the latest version provided by the vendor.
3
What versions of Tenda AX1806 are affected by CVE-2024-35578?
CVE-2024-35578 affects Tenda AX1806 version v1.0.0.1.
4
What is the impact of CVE-2024-35578?
The impact of CVE-2024-35578 includes potential unauthorized access and disruption of services due to remote code execution.
5
How does CVE-2024-35578 exploit the vulnerable parameter?
CVE-2024-35578 exploits the vulnerable adv.iptv.stballvlans parameter in the formSetIptv function to trigger a stack overflow.