CVE-2024-42634

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
16/08/2024
Last modified:
11/04/2025

Description

A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:ac9_firmware:15.03.06.42:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac9:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools