CVE-2024-35580: Critical severity tenda ax1806 firmware vulnerability
Published May 20, 2024
·Updated
Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
Affected Software
3 affected components
Tenda AX1806
All of the following
Tenda Ax1806 Firmware=1.0.0.1
Tenda AX1806
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 20, 2024
CVE Published
via NVD·06:15 PM
Aug 20, 2024
Data Sourced
via MITRE·02:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35580?
CVE-2024-35580 is classified as a high-severity vulnerability due to the potential for remote code execution resulting from a stack overflow.
2
How do I fix CVE-2024-35580?
To fix CVE-2024-35580, update the Tenda AX1806 firmware to the latest version provided by the vendor.
3
What types of devices are affected by CVE-2024-35580?
CVE-2024-35580 specifically affects the Tenda AX1806 router model.
4
What is the attack vector for CVE-2024-35580?
The attack vector for CVE-2024-35580 involves sending crafted requests to the adv.iptv.stbpvid parameter in the formSetIptv function.
5
Can CVE-2024-35580 be exploited remotely?
Yes, CVE-2024-35580 can be exploited remotely if an attacker has access to the vulnerable device's network.