CVE-2024-45414
About
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.
Rainforest analyst review
The HTTPD binary in a range of ZTE routers overflows a stack buffer in its webPrivateDecrypt function: it base64-decodes attacker-supplied ciphertext, decrypts it, and copies the result onto the stack without checking the length. An unauthenticated attacker who can reach the web interface gets remote code execution as root — total control of the router, from the outside, with no credentials.
This is the worst-case profile for edge networking gear: no authentication, root-level execution, and a widely shared binary across multiple router models, which means one working exploit generalizes across a large device population. That's precisely what mass-scanning actors build router botnets from, and an unauthenticated stack overflow in exposed HTTPD is a reliable, scriptable takeover once details are public.
Our response centers on exposure and model-level inventory. We identify which ZTE models we run and whether any expose their web management interface to untrusted networks, because that reachability is the entire risk. It's also worth pairing with its sibling in the same binary — an attacker probing one of these router flaws is likely testing the others — so we treat the affected HTTPD as a single surface to get off the public side and patched together.
References
Related CVEs
Frequently asked questions
What is CVE-2024-45414?
The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, the encrypted data is supplied base64 encoded. The decoded ciphertext is stored on the stack without checking its length. An unauthenticated attacker can get RCE as root by exploiting this vulnerability.
How severe is CVE-2024-45414?
CVE-2024-45414 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2024-45414 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
How do I fix CVE-2024-45414?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
