Stack-Based Buffer Overflow in Tenda FH1203 Router
CVE-2024-2990
8.8HIGH
What is CVE-2024-2990?
A stack-based buffer overflow vulnerability has been identified in the Tenda FH1203 router that arises from improper handling of user-supplied input within the execCommand function found in the /goform/execCommand file. This flaw allows attackers to craft malicious commands that, when executed, could lead to arbitrary code execution on the device. The vulnerability can be exploited remotely without requiring physical access, thereby posing a significant security risk. Despite attempts to notify the vendor prior to its public disclosure, no response has been received, leaving users potentially vulnerable to attacks that could compromise their network.