CVE-2024-48826: Command Injection
Published Oct 28, 2024
·Updated
Tenda AC7 v.15.03.06.44 ateiwprivset has pre-authentication command injection allowing remote attackers to execute arbitrary code.
Affected Software
3 affected components
Tenda AC7
All of the following
Tenda AC7 firmware=15.03.06.44
Tenda AC7
Event History
Oct 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-48826?
CVE-2024-48826 is rated as critical due to its potential for remote code execution without authentication.
2
What are the affected devices for CVE-2024-48826?
CVE-2024-48826 affects Tenda AC7, AC9, and AC10 routers with firmware version 15.03.06.44.
3
How do I fix CVE-2024-48826?
To mitigate CVE-2024-48826, update the router firmware to the latest version provided by Tenda.
4
Can CVE-2024-48826 be exploited remotely?
Yes, CVE-2024-48826 can be exploited remotely by attackers to execute arbitrary commands.
5
What is the nature of the vulnerability in CVE-2024-48826?
CVE-2024-48826 involves a pre-authentication command injection vulnerability that allows attackers to execute arbitrary code.