PT-2024-9598 · Tenda · Tenda G3
Published
2024-09-30
·
Updated
2024-11-14
·
CVE-2024-50852
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda G3 version 3.0 v15.11.0.20
Description
The issue is related to the formSetUSBPartitionUmount function of the Tenda G3 wireless access point's firmware, which fails to neutralize special elements when processing the
usbPartitionName parameter. This can be exploited by a remote attacker to execute arbitrary commands by sending a specially crafted POST request.Recommendations
For Tenda G3 version 3.0 v15.11.0.20, consider disabling the
formSetUSBPartitionUmount function until a patch is available to prevent potential command injection attacks. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the usbPartitionName parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda G3