Stack-Based Buffer Overflow in Tenda FH1202 Router
CVE-2024-2980
8.8HIGH
What is CVE-2024-2980?
A stack-based buffer overflow vulnerability has been identified in the Tenda FH1202 router, specifically in the execCommand function of the /goform/execCommand file. This flaw allows attackers to manipulate the cmdinput argument, potentially leading to execution of arbitrary code. The vulnerability can be exploited remotely, posing significant risks to users. Despite early notification to the vendor regarding the discovery, no response has been received, underlining the urgency for users to apply necessary security measures.