CVE-2024-48192: High severity tenda g3 firmware vulnerability
Published Oct 17, 2024
·Updated
Tenda G3 v15.01.0.5(2848755)EN was discovered to contain a hardcoded password vulnerability in /etcro/shadow, which allows attackers to log in as root
Affected Software
3 affected components
Tenda G3
All of the following
Tenda G3 Firmware=15.01.0.5\(2848_755\)_en
Tenda G3
Event History
Oct 17, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-48192?
CVE-2024-48192 is classified as a high-severity vulnerability due to the presence of a hardcoded password that allows root access.
2
How do I fix CVE-2024-48192?
To remediate CVE-2024-48192, users should update the Tenda G3 router firmware to the latest version provided by Tenda.
3
What devices are affected by CVE-2024-48192?
CVE-2024-48192 specifically affects the Tenda G3 router running firmware version 15.01.0.5(2848_755)_EN.
4
What exploitation methods are available for CVE-2024-48192?
Exploiting CVE-2024-48192 allows attackers to log in as root using the hardcoded password found in the /etc_ro/shadow file.
5
Is there a patch available for CVE-2024-48192?
Yes, a patch or firmware update is typically provided by Tenda to resolve CVE-2024-48192.