CVE-2024-10280
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Published:Oct 23, 2024
Last Modified:Nov 1, 2024
EPS:Oct 23, 2024
EPSS Score:0.0039
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Tenda
Product
Ac10
Tenda
Ac10
Vendor
Tenda
Product
Ac10 Firmware
Tenda
Ac10 Firmware
Vendor
Tenda
Product
Ac10u
Tenda
Ac10u
Vendor
Tenda
Product
Ac10u Firmware
Tenda
Ac10u Firmware
Vendor
Tenda
Product
Ac1206
Tenda
Ac1206
Vendor
Tenda
Product
Ac1206 Firmware
Tenda
Ac1206 Firmware
Vendor
Tenda
Product
Ac15
Tenda
Ac15
Vendor
Tenda
Product
Ac15 Firmware
Tenda
Ac15 Firmware
Vendor
Tenda
Product
Ac18
Tenda
Ac18
Vendor
Tenda
Product
Ac18 Firmware
Tenda
Ac18 Firmware
Vendor
Tenda
Product
Ac500
Tenda
Ac500
Vendor
Tenda
Product
Ac500 Firmware
Tenda
Ac500 Firmware
Vendor
Tenda
Product
Ac6
Tenda
Ac6
Vendor
Tenda
Product
Ac6 Firmware
Tenda
Ac6 Firmware
Vendor
Tenda
Product
Ac7
Tenda
Ac7
Vendor
Tenda
Product
Ac7 Firmware
Tenda
Ac7 Firmware
Vendor
Tenda
Product
Ac8
Tenda
Ac8
Vendor
Tenda
Product
Ac8 Firmware
Tenda
Ac8 Firmware
Vendor
Tenda
Product
Ac9
Tenda
Ac9
Vendor
Tenda
Product
Ac9 Firmware
Tenda
Ac9 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
