Stack-based Buffer Overflow in Tenda FH1203 Router
CVE-2024-2989
8.8HIGH
Summary
A stack-based buffer overflow vulnerability exists in the Tenda FH1203 router, specifically within the fromNatStaticSetting function of the /goform/NatStaticSetting file. This flaw allows an attacker to manipulate the argument page, potentially leading to remote code execution. The vulnerability has been publicly disclosed, and the absence of a response from the vendor raises concerns regarding the security of users relying on this device. Immediate action is recommended to mitigate potential risks.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published