CVE-2024-4165
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-4165 is a critical vulnerability affecting the Tenda G3 firmware version 15.11.0.17(9502). The issue lies within the modifyDhcpRule function of the /goform/modifyDhcpRule file. An attacker can exploit this stack-based buffer overflow vulnerability by manipulating the bindDhcpIndex argument. This exploit can be executed remotely, making it a serious threat. The vulnerability identifier is VDB-261984, and the exploit has been made public, increasing the risk. Despite early contact, the vendor has not responded to disclose a patch or mitigation strategy.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.