Lyrie.Ai
Critical Vulnerabilities in ncurses and Tenda Firmware Expose Systems to Remote Code Execution
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two critical vulnerabilities have been identified: CVE-2017-10684 in ncurses 6.0 and CVE-2024-51311 in Tenda TX9 firmware. CVE-2017-10684 involves a stack-based buffer overflow in the fmt_entry function, allowing remote arbitrary code execution. CVE-2024-51311 also features a stack overflow vulnerability in the sub_4418CC function of Tenda's firmware. Both vulnerabilities have a CVSS score of 9.8, indicating their severity. The vulnerabilities were validated by Lyrie's Threat Intelligence Pipeline with confirmations from three independent sources. No active exploitation has been reported yet, but the potential for remote code execution poses significant risks. Organizations using affected systems are advised to monitor for updates and apply patches as they become available. Continuous autonomous monitoring is recommended to mitigate risks associated with these vulnerabilities.
Key Points: • CVE-2017-10684 in ncurses allows remote code execution via a stack-based buffer overflow. • CVE-2024-51311 affects Tenda TX9 firmware, also enabling remote code execution through a stack overflow. • Both vulnerabilities have a CVSS score of 9.8, indicating critical severity.