CVE-2024-42634

A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.
References
Link Resource
https://github.com/goldds96/Report/blob/main/Tenda/AC9/CI.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac9_firmware:15.03.06.42:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac9:-:*:*:*:*:*:*:*

History

11 Apr 2025, 15:13

Type Values Removed Values Added
CPE cpe:2.3:o:tenda:ac9_firmware:15.03.06.42:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac9:-:*:*:*:*:*:*:*
References () https://github.com/goldds96/Report/blob/main/Tenda/AC9/CI.md - () https://github.com/goldds96/Report/blob/main/Tenda/AC9/CI.md - Exploit, Third Party Advisory
First Time Tenda ac9 Firmware
Tenda ac9
Tenda

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en formWriteFacMac del binario httpd en Tenda AC9 v15.03.06.42. Como resultado, el atacante puede ejecutar comandos del sistema operativo con privilegios de superusuario.

16 Aug 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

16 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-16 16:15

Updated : 2025-04-11 15:13


NVD link : CVE-2024-42634

Mitre link : CVE-2024-42634

CVE.ORG link : CVE-2024-42634


JSON object : View

Products Affected

tenda

  • ac9_firmware
  • ac9
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')