Tenda F1203 openSchedWifi setSchedWifi stack-based overflow
CVE-2024-2979
8.8HIGH
What is CVE-2024-2979?
A stack-based buffer overflow vulnerability exists in the Tenda F1203 product, specifically within the setSchedWifi function located in the /goform/openSchedWifi file. This vulnerability arises from improper handling of the arguments schedStartTime and schedEndTime, allowing a remote attacker to manipulate these parameters and potentially execute arbitrary code. The flaw was disclosed publicly, making it a prime target for malicious exploitation. Despite early notification to the vendor regarding this vulnerability disclosure, there has been no response.
Affected Version(s)
F1203 2.0.1.6