Critical Vulnerabilities in ncurses and Tenda Firmware Expose Systems to Remote Code Execution
ID: 93ff92b5-0b40-5a6f-b673-3b4db578fee6
STIX ID: report--93ff92b5-0b40-5a6f-b673-3b4db578fee6
Feed Name: ThreatCluster
Threat Score
Two critical remote code execution vulnerabilities were identified: CVE-2017-10684 in ncurses 6.0 (stack-based buffer overflow in fmt_entry) and CVE-2024-51311 in Tenda TX9 firmware (stack overflow in sub_4418CC). Both carry CVSS 9.8 severity, were validated by multiple sources, and — while no active exploitation has been observed — organizations are advised to monitor for updates, apply patches, and maintain continuous autonomous monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
