Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvqq-m3qc-q58j

Опубликовано: 23 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 54%
0.00306
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 6.5
nvd
10 месяцев назад

A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость функции websReadEvent микропрограммного обеспеченеия маршрутизаторов Tenda AC, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 54%
0.00306
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-476