CVE-2024-48825: Command Injection
Published Oct 28, 2024
·Updated
Tenda AC7 v.15.03.06.44 ateifconfigset has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Affected Software
3 affected components
Tenda AC7
All of the following
Tenda AC7 firmware=15.03.06.44
Tenda AC7
Event History
Oct 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-48825?
CVE-2024-48825 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2024-48825?
To fix CVE-2024-48825, update your Tenda AC7 router firmware to the latest version provided by the manufacturer.
3
Who is affected by CVE-2024-48825?
CVE-2024-48825 affects users of Tenda AC7 routers running version 15.03.06.44.
4
What type of vulnerability is CVE-2024-48825?
CVE-2024-48825 is a pre-authentication command injection vulnerability.
5
Can CVE-2024-48825 be exploited remotely?
Yes, CVE-2024-48825 can be exploited remotely by attackers to execute arbitrary code without authentication.