Stack-Based Buffer Overflow in Tenda FH1203 Router
CVE-2024-2990
8.8HIGH
Summary
A stack-based buffer overflow vulnerability has been identified in the Tenda FH1203 router that arises from improper handling of user-supplied input within the execCommand function found in the /goform/execCommand file. This flaw allows attackers to craft malicious commands that, when executed, could lead to arbitrary code execution on the device. The vulnerability can be exploited remotely without requiring physical access, thereby posing a significant security risk. Despite attempts to notify the vendor prior to its public disclosure, no response has been received, leaving users potentially vulnerable to attacks that could compromise their network.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published