logo

Critical Vulnerabilities in ncurses and Tenda Firmware Expose Systems to Remote Code Execution

ID: 93ff92b5-0b40-5a6f-b673-3b4db578fee6

STIX ID: report--93ff92b5-0b40-5a6f-b673-3b4db578fee6

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

Two critical remote code execution vulnerabilities were identified: CVE-2017-10684 in ncurses 6.0 (stack-based buffer overflow in fmt_entry) and CVE-2024-51311 in Tenda TX9 firmware (stack overflow in sub_4418CC). Both carry CVSS 9.8 severity, were validated by multiple sources, and — while no active exploitation has been observed — organizations are advised to monitor for updates, apply patches, and maintain continuous autonomous monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.