First published: Wed Apr 17 2024(Updated: )
A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261144. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda AC500 firmware | =2.0.1.9\(1307\) | |
Tenda AC500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3908 is classified as critical due to its potential for remote command injection.
To fix CVE-2024-3908, it is recommended to update the Tenda AC500 firmware to the latest version.
CVE-2024-3908 affects the Tenda AC500 running firmware version 2.0.1.9(1307).
CVE-2024-3908 is a command injection vulnerability that allows an attacker to execute arbitrary commands.
Yes, CVE-2024-3908 can be exploited remotely, making it particularly dangerous.