CVE-2024-10280
MEDIUMTenda AC6-AC1206 <20241022 - Null Pointer Dereference
Title source: llmDescription
A vulnerability was found in Tenda AC6, AC7, AC8, AC9, AC10, AC10U, AC15, AC18, AC500 and AC1206 up to 20241022. It has been rated as problematic. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.281555
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.281555
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.426417
Third Party Advisory exploit
https://github.com/JohenanLi/router_vuls/blob/main/websReadEvent/websReadEvent.md
Product product
https://www.tenda.com.cn/
Scores
CVSS v3
6.5
EPSS
0.0016
EPSS Percentile
37.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (22)
tenda/ac10_firmware
16.03.10.13
tenda/ac10_firmware
16.03.10.20
tenda/ac10_firmware
16.03.48.19
tenda/ac10_firmware
16.03.48.23
tenda/ac10u_firmware
15.03.06.48
tenda/ac10u_firmware
15.03.06.49
tenda/ac1206_firmware
15.03.06.23
tenda/ac15_firmware
15.03.05.18
tenda/ac15_firmware
15.03.05.19
tenda/ac18_firmware
15.03.05.05
... and 12 more
Published
Oct 23, 2024
Tracked Since
Feb 18, 2026