7.5

CVE-2024-10280

A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TendaAc15 Firmware Version15.03.05.18
   TendaAc15 Version-
TendaAc15 Firmware Version15.03.05.19
   TendaAc15 Version-
TendaAc7 Firmware Version15.03.06.44
   TendaAc7 Version-
TendaAc10u Firmware Version15.03.06.48
   TendaAc10u Version-
TendaAc10u Firmware Version15.03.06.49
   TendaAc10u Version-
TendaAc500 Firmware Version1.0.0.14
   TendaAc500 Version-
TendaAc500 Firmware Version1.0.0.16
   TendaAc500 Version-
TendaAc500 Firmware Version2.0.1.9(1307)
   TendaAc500 Version-
TendaAc18 Firmware Version15.03.05.05
   TendaAc18 Version-
TendaAc18 Firmware Version15.03.05.19(6318)
   TendaAc18 Version-
TendaAc9 Firmware Version15.03.2.13
   TendaAc9 Version1.0
TendaAc9 Firmware Version15.03.05.14
   TendaAc9 Version1.0
TendaAc9 Firmware Version15.03.05.19(6318)
   TendaAc9 Version1.0
TendaAc9 Firmware Version15.03.06.42
   TendaAc9 Version3.0
TendaAc1206 Firmware Version15.03.06.23
   TendaAc1206 Version-
TendaAc6 Firmware Version15.03.06.23
   TendaAc6 Version2.0
TendaAc10 Firmware Version16.03.10.13
   TendaAc10 Version4.0
TendaAc10 Firmware Version16.03.10.20
   TendaAc10 Version4.0
TendaAc10 Firmware Version16.03.48.19
   TendaAc10 Version5.0
TendaAc10 Firmware Version16.03.48.23
   TendaAc10 Version5.0
TendaAc8 Firmware Version16.03.34.06
   TendaAc8 Version4.0
TendaAc8 Firmware Version16.03.34.09
   TendaAc8 Version4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.441
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cna@vuldb.com 7.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cna@vuldb.com 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.