CVE-2024-32314(tenda / ac500)

LOWCVSS 3.8 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac500
  • ac500_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ac500ac500_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets32 URLs
Full discourse1 post
  • RST Cloud@rst_cloud

    #threatreport #LowCompleteness ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure | 05-10-2026 Source: https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure Key details below ↓ 💀Threats: Clingstun, 🎯Victims: Internet facing devices, Iot devices, Linux devices, Routers 🔓CVEs: CVE-2026-87827 \[[Vulners](https://vulners.com/cve/CVE-2026-87827)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-10915 \[[Vulners](https://vulners.com/cve/CVE-2024-10915)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2024-3721 \[[Vulners](https://vulners.com/cve/CVE-2024-3721)] - CVSS V3.1: *6.3*, - Vulners: Exploitation: True CVE-2019-7256 \[[Vulners](https://vulners.com/cve/CVE-2019-7256)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - nortekcontrol linear_emerge_essential_firmware (le1.00-06) CVE-2016-20016 \[[Vulners](https://vulners.com/cve/CVE-2016-20016)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - mvpower tv-7104he_firmware (1.8.4_115215b9) CVE-2024-32292 \[[Vulners](https://vulners.com/cve/CVE-2024-32292)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda w30e_firmware (1.0.1.25\(633\)) CVE-2021-35394 \[[Vulners](https://vulners.com/cve/CVE-2021-35394)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - realtek rtl819x_jungle_software_development_kit (le3.4.14b) CVE-2024-32281 \[[Vulners](https://vulners.com/cve/CVE-2024-32281)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac7_firmware (15.03.06.44) CVE-2024-32314 \[[Vulners](https://vulners.com/cve/CVE-2024-32314)] - CVSS V3.1: *3.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac500_firmware (2.0.1.9\(1307\)) CVE-2025-67038 \[[Vulners](https://vulners.com/cve/CVE-2025-67038)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lantronix eds5008_firmware (<2.2.0.0r1) CVE-2024-46048 \[[Vulners](https://vulners.com/cve/CVE-2024-46048)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda fh451_firmware (1.0.0.9) CVE-2023-26801 \[[Vulners](https://vulners.com/cve/CVE-2023-26801)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lb-link bl-lte300_firmware (1.0.8) CVE-2022-37055 \[[Vulners](https://vulners.com/cve/CVE-2022-37055)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink go-rt-ac750_firmware (2.00b02) CVE-2023-41011 \[[Vulners](https://vulners.com/cve/CVE-2023-41011)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - chinamobile intelligent_home_gateway_firmware (hg6543c4) CVE-2022-35555 \[[Vulners](https://vulners.com/cve/CVE-2022-35555)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - tenda w6_firmware (1.0.0.9\(4122\)) CVE-2024-10914 \[[Vulners](https://vulners.com/cve/CVE-2024-10914)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2023-1389 \[[Vulners](https://vulners.com/cve/CVE-2023-1389)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - tp-link archer_ax21_firmware (<1.1.4) CVE-2024-7029 \[[Vulners](https://vulners.com/cve/CVE-2024-7029)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - avtech avm1203_firmware (lefullimg-1023-1007-1011-1009) CVE-2025-34035 \[[Vulners](https://vulners.com/cve/CVE-2025-34035)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - engeniustech esr300_firmware (1.1.0.28, 1.3.1.42, 1.4.0, 1.4.1.28, 1.4.2) CVE-2024-23624 \[[Vulners](https://vulners.com/cve/CVE-2024-23624)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2022-36553 \[[Vulners](https://vulners.com/cve/CVE-2022-36553)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - hytec hwl-2511-ss_firmware (le1.05) CVE-2019-17621 \[[Vulners](https://vulners.com/cve/CVE-2019-17621)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-859_firmware (le1.05b03, 1.06b01) CVE-2026-36356 \[[Vulners](https://vulners.com/cve/CVE-2026-36356)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True CVE-2025-34037 \[[Vulners](https://vulners.com/cve/CVE-2025-34037)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-23625 \[[Vulners](https://vulners.com/cve/CVE-2024-23625)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2024-35340 \[[Vulners](https://vulners.com/cve/CVE-2024-35340)] - CVSS V3.1: *8.6*, - Vulners: Exploitation: Unknown Soft: - tenda fh1206_firmware (1.2.0.8\(8155\)) CVE-2023-46805 \[[Vulners](https://vulners.com/cve/CVE-2023-46805)] - CVSS V3.1: *8.2*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2024-21887 \[[Vulners](https://vulners.com/cve/CVE-2024-21887)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2022-26289 \[[Vulners](https://vulners.com/cve/CVE-2022-26289)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda m3_firmware (1.0.0.12\(4856\)) CVE-2014-8361 \[[Vulners](https://vulners.com/cve/CVE-2014-8361)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-905l_firmware (le2.05b01) CVE-2021-36380 \[[Vulners](https://vulners.com/cve/CVE-2021-36380)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - sunhillo sureline (<8.7.0.1.1) 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036, T1037, T1057, T1071, T1090, T1105, T1190, T1547, T1564 🧨IOCs: - IP: 3 - File: 5 - Hash: 21 💽Software: Linux, WebRTC, Ivanti, Tenda, LB-LINK 💻Platforms: mips, arm, intel #threatreport: ClingSTUN is a Linux backdoor that exploits Internet-facing, unpatched devices and converts them into remotely controlled proxy nodes. Initial delivery was observed through exploitation of CVE-2022-36553, a command-injection vulnerability in Hytec Inter HWL-2511-SS routers. Subsequent campaigns used command injection in the EnGenius IoT cloud service (CVE-2025-34035), D-Link UPnP (CVE-2024-23625), Linear and other IoT devices, Realtek devices affected by CVE-2021-35394, TP-Link Archer AX21 devices affected by CVE-2023-1389, AVTECH AVM1203 devices affected by CVE-2024-7029, and D-Link devices affected by CVE-2024-10915. The attackers also used a buffer overflow in the `goform` name parameter across multiple device vendors. ClingSTUN downloaders move to `/tmp`, retrieve architecture-specific payloads, and execute versions for ARM, Intel 80386, MIPS, PowerPC, and AMD x86-64 systems. A later downloader scans `/proc/mounts`, unmounts selected mount points, kills associated processes, and terminates processes running from `/tmp`. The malware also enumerates `/proc`, identifies competing or suspicious processes, compares process command lines with executable names, and kills processes that fail its checks. It opens watchdog device files and uses `ioctl` to disable watchdog timers. For persistence, ClingSTUN copies itself to `/root/.cling` and `/usr/local/bin/.cling`, sets executable permissions, and appends these files to three startup-related files so they execute during boot. It clears its command-line arguments to hide activity from process-monitoring tools. When running as root, it copies selected files from `/proc/1` into `/tmp` and bind-mounts the directory over its own `/proc` entry to conceal process information. The backdoor uses UDP sockets and standard 20-byte STUN binding requests to contact public STUN services, discover externally mapped addresses and ports, and maintain NAT bindings. Earlier versions contacted 24 endpoints and required at least half to respond; a later version used 13 endpoints and required all to succeed. It periodically sends a group identifier and mapped-port data to these services. A specially formatted 20-byte operator packet can trigger remote command execution: command 1 causes the malware to establish an outbound TCP connection, receive a command, and execute it. ClingSTUN also contains hard-coded exploits for self-propagation.

    0000093
    829 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac500---
OStendaac500_firmware2.0.1.9\(1307\)--

Explore more