CVE-2024-42634

A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.
Configurations

No configuration.

History

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en formWriteFacMac del binario httpd en Tenda AC9 v15.03.06.42. Como resultado, el atacante puede ejecutar comandos del sistema operativo con privilegios de superusuario.

16 Aug 2024, 18:35

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

16 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-16 16:15

Updated : 2024-08-19 13:00


NVD link : CVE-2024-42634

Mitre link : CVE-2024-42634

CVE.ORG link : CVE-2024-42634


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')