Stack-Based Buffer Overflow Vulnerability in Tenda FH1206
CVE-2024-34942

8.8HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
14 May 2024

Summary

The Tenda FH1206 device version V1.2.0.8(8155)_EN is susceptible to a stack-based buffer overflow vulnerability through the funcpara1 parameter at the ip/goform/exeCommand endpoint. This vulnerability may allow an attacker to execute arbitrary code or gain unauthorized access to the system, potentially leading to escalated privileges and control over the affected device. It emphasizes the importance of securing IoT devices and regular patching to mitigate the risks associated with such vulnerabilities.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.