CVE-2024-11650: Tenda i9 Firmware

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Tenda i9 Firmware: version 1.0.0.8(3828) only

Published 2024-11-25. Last modified 2026-06-17.