CVE-2024-30612

Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac10u_firmware:15.03.06.48:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac10u:-:*:*:*:*:*:*:*

History

17 Mar 2025, 14:21

Type Values Removed Values Added
First Time Tenda ac10u
Tenda
Tenda ac10u Firmware
References () https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC10U/v1.V15.03.06.48/more/formSetClientState.md - () https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC10U/v1.V15.03.06.48/more/formSetClientState.md - Broken Link, Exploit, Third Party Advisory
CPE cpe:2.3:o:tenda:ac10u_firmware:15.03.06.48:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac10u:-:*:*:*:*:*:*:*

21 Nov 2024, 09:12

Type Values Removed Values Added
References () https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC10U/v1.V15.03.06.48/more/formSetClientState.md - () https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC10U/v1.V15.03.06.48/more/formSetClientState.md -

01 Aug 2024, 15:35

Type Values Removed Values Added
Summary
  • (es) Tenda AC10U v15.03.06.48 tiene una vulnerabilidad de desbordamiento de la región stack de la memoria en el parámetro deviceId, limitSpeed, limitSpeedUp de la función formSetClientState.
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

28 Mar 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-28 15:15

Updated : 2025-03-17 14:21


NVD link : CVE-2024-30612

Mitre link : CVE-2024-30612

CVE.ORG link : CVE-2024-30612


JSON object : View

Products Affected

tenda

  • ac10u_firmware
  • ac10u
CWE
CWE-121

Stack-based Buffer Overflow