CVE-2024-7581

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Aug 7, 2024
CWE ID 787
CWE ID 121

Summary

CVE-2024-7581 is a newly disclosed critical vulnerability that impacts the Tenda A301 router running version 15.13.08.12. The issue resides in the function formWifiBasicSet of the /goform/WifiBasicSet file, where the security argument is susceptible to stack-based buffer overflow. An attacker can exploit this remotely, leading to potential code execution. Although the vulnerability has been made public, the vendor has yet to issue a patch or confirm any communication regarding a fix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share