Stack Overflow Vulnerability in Tenda FH1201 by Tenda Technology
CVE-2024-42949

7.5HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
15 August 2024

Summary

The Tenda FH1201 version 1.2.0.14 has a vulnerability that allows for a stack overflow through manipulation of the qos parameter in the fromqossetting function. Attackers can exploit this flaw by sending specially crafted POST requests, resulting in a Denial of Service (DoS). This presents a serious risk to users of the affected product, as the device may become unresponsive. Proper measures should be taken to mitigate this issue and protect the integrity of the network.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.