CVE-2024-0540
published 2024-01-15CVE-2024-0540: A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. Affected is the function formOfflineSet of the component httpd. The…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.79%
52.3th percentile
A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. Affected is the function formOfflineSet of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250710 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | w9 | — | — |
| tenda | w9_firmware | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET REMOTE_ACCESS MS Terminal Server Root login
suricata·2011-04-22
CVE-2001-0540 ET REMOTE_ACCESS MS Terminal Server Root login
ET REMOTE_ACCESS MS Terminal Server Root login
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 3389 (msg:"ET REMOTE_ACCESS MS Terminal Server Root login"; flow:established,to_server; content:"|03 00 00|"; depth:3; content:"|e0 00 00 00 00 00|"; distance:2; within:6; content:"Cookie|3a| mstshash=root|0d 0a|"; nocase; reference:cve,2001-0540; classtype:protocol-command-decode; sid:2012710; rev:2; metadata:created_at 2011_04_22, cve CVE_2001_0540, former_category INFO, confidence Medium, signature_severity Unknown, updated_at 2024_06_27;)
Suricata
ET REMOTE_ACCESS MS Remote Desktop Administrator Login Request
suricata·2011-04-22
ET REMOTE_ACCESS MS Remote Desktop Administrator Login Request
ET REMOTE_ACCESS MS Remote Desktop Administrator Login Request
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 3389 (msg:"ET REMOTE_ACCESS MS Remote Desktop Administrator Login Request"; flow:established,to_server; content:"|03 00 00|"; depth:3; content:"|e0 00 00 00 00 00|"; distance:2; within:6; content:"Cookie|3a| mstshash=admin"; distance:0; nocase; reference:cve,CAN-2001-0540; classtype:protocol-command-decode; sid:2012709; rev:6; metadata:created_at 2011_04_22, former_category INFO, confidence Medium, signature_severity Unknown, updated_at 2024_06_27;)
Suricata
ET INFO MS Remote Desktop Service User Login Request
suricata·2011-04-22
ET INFO MS Remote Desktop Service User Login Request
ET INFO MS Remote Desktop Service User Login Request
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 3389 (msg:"ET INFO MS Remote Desktop Service User Login Request"; flow:established,to_server; content:"|03 00 00|"; depth:3; content:"|e0 00 00 00 00 00|"; distance:2; within:6; content:"Cookie|3a| mstshash=service|0d 0a|"; nocase; reference:cve,CAN-2001-0540; classtype:protocol-command-decode; sid:2012712; rev:2; metadata:created_at 2011_04_22, confidence High, signature_severity Informational, updated_at 2024_03_06;)
Suricata
ET INFO MS Remote Desktop POS User Login Request
suricata·2011-04-22
CVE-2001-0540 ET INFO MS Remote Desktop POS User Login Request
ET INFO MS Remote Desktop POS User Login Request
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 3389 (msg:"ET INFO MS Remote Desktop POS User Login Request"; flow:established,to_server; content:"|03 00 00|"; depth:3; content:"|e0 00 00 00 00 00|"; distance:2; within:6; content:"Cookie|3a| mstshash=pos|0d 0a|"; nocase; reference:cve,2001-0540; classtype:protocol-command-decode; sid:2012711; rev:2; metadata:created_at 2011_04_22, cve CVE_2001_0540, confidence High, signature_severity Informational, updated_at 2024_03_06;)
No public exploits indexed.
No writeups or analysis indexed.
2024-01-15
Published