Stack Overflow Vulnerability in Tenda FH1206 Router
CVE-2024-42979
7.5HIGH
Summary
The Tenda FH1206 router suffers from a significant stack overflow vulnerability due to improper handling of the page parameter in the frmL7ProtForm function. When a specially crafted POST request is sent to this function, it can trigger a Denial of Service (DoS) condition, rendering the device inoperable. This flaw highlights critical concerns regarding the security of IoT devices and emphasizes the need for timely updates and patches to protect against potential exploitation.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database