CVE-2024-50667: Critical severity trendnet tew-820ap vulnerability
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50667?
CVE-2024-50667 has been classified as a medium severity vulnerability due to its potential for stack overflow attacks.
How do I fix CVE-2024-50667?
To mitigate CVE-2024-50667, update the Trendnet TEW-820AP firmware to the latest version provided by Trendnet.
Which devices are affected by CVE-2024-50667?
CVE-2024-50667 specifically affects the Trendnet TEW-820AP model running firmware version 1.01.B01.
What are the potential impacts of CVE-2024-50667?
Exploitation of CVE-2024-50667 could lead to arbitrary code execution or denial of service due to stack overflow.
How can attackers exploit CVE-2024-50667?
Attackers can exploit CVE-2024-50667 by sending specially crafted IPv6 address payloads to the vulnerable endpoints.