Tenda FH1205 execCommand formexeCommand stack-based overflow
CVE-2024-3008
What is CVE-2024-3008?
A security vulnerability has been identified in the Tenda FH1205 router, specifically in the formexeCommand function located in the /goform/execCommand file. This issue stems from improper handling of the cmdinput argument, leading to a stack-based buffer overflow. The exploit can be executed remotely, potentially allowing attackers to gain unauthorized access or control over the device. Although the vulnerability has been publicly disclosed, communication with the vendor regarding this issue has not been acknowledged. Users of the affected product are advised to take immediate precautions to safeguard their devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FH1205 2.0.0.7(775)
References
CVSS V3.1
CVSS V3.0
Timeline
- ๐พ
Exploit known to exist
Vulnerability published