CVE-2024-44550

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 26, 2024
Updated: Aug 27, 2024
CWE ID 121
CWE ID 787

Summary

CVE-2024-44550 is a critical vulnerability affecting the Tenda AX1806 firmware version 1.0.0.1, which contains a stack overflow in the formGetIptv function due to improper handling of the adv.iptv.stbpvid parameter. The vulnerability has an exploitability score of 3.9 and a base severity rating of 9.8, indicating that exploitation could lead to high impacts on integrity, confidentiality, and availability with no user interaction required. To remediate this issue, organizations should update the affected firmware to the latest version provided by Tenda as soon as possible. If exploited, this vulnerability could allow attackers to execute arbitrary code remotely, potentially compromising sensitive data and disrupting services. This situation highlights a significant security risk for organizations using vulnerable Tenda devices within their networks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share