CVE-2024-2486
published 2024-03-15CVE-2024-2486: A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file…
PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.56%
72.4th percentile
A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256893 was assigned to this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac18 | — | — |
| tenda | ac18_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5c3h-74f7-rvqq: A vulnerability was found in Tenda AC18 15
ghsa_unreviewed·2024-03-15
CVE-2024-2486 [HIGH] CWE-121 GHSA-5c3h-74f7-rvqq: A vulnerability was found in Tenda AC18 15
A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256893 was assigned to this vulnerability.
Red Hat
edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
vendor_redhat·2025-11-26·CVSS 6.7
CVE-2025-2486 [MEDIUM] CWE-489 edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
edk2: edk2: UEFI Shell access in Secure Boot environments allows bypass of Secure Boot constraints
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
A flaw was found in edk2. This vulnerability allows bypass of Secure Boot (Unified Extensible Firmware Interface) constraints via accidentally allowing the UEFI Shell to be accessed in Secure Boot envi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-03-15
Published