Stack-Based Buffer Overflow Vulnerability in Tenda FH1206
CVE-2024-34942
8.8HIGH
What is CVE-2024-34942?
The Tenda FH1206 device version V1.2.0.8(8155)_EN is susceptible to a stack-based buffer overflow vulnerability through the funcpara1 parameter at the ip/goform/exeCommand endpoint. This vulnerability may allow an attacker to execute arbitrary code or gain unauthorized access to the system, potentially leading to escalated privileges and control over the affected device. It emphasizes the importance of securing IoT devices and regular patching to mitigate the risks associated with such vulnerabilities.