VYPR
Critical severity9.8NVD Advisory· Published Aug 16, 2024· Updated Jun 17, 2026

CVE-2024-42634

CVE-2024-42634

Description

A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.

Affected products

3
  • Tenda/AC9llm-fuzzy2 versions
    15.03.06.42+ 1 more
    • (no CPE)range: 15.03.06.42
    • (no CPE)
  • cpe:2.3:o:tenda:ac9_firmware:15.03.06.42:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.