Tenda F1203 setcfm formSetCfm stack-based overflow
CVE-2024-2978
Key Information:
Badges
Summary
A stack-based buffer overflow vulnerability has been identified in the Tenda F1203 product, specifically affecting version 2.0.1.6 through the formSetCfm function located in the /goform/setcfm file. This flaw is triggered by improper manipulation of the argument funcpara1, enabling the possibility of remote exploitation. The vulnerability has been publicly disclosed, raising concerns about its potential for abuse. The vendor was informed of this issue prior to disclosure but has yet to respond.
Affected Version(s)
F1203 2.0.1.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published