Stack Overflow Vulnerability in Tenda FH1206 v02.03.01.35 Allows DoS via POST Request
CVE-2024-42985
7.5HIGH
Summary
The Tenda FH1206, specifically version 02.03.01.35, is impacted by a vulnerability that allows for a stack overflow through improper handling of the page parameter within the fromNatlimit function. This security flaw can be exploited by attackers to perform a Denial of Service (DoS) attack, disrupting the normal operation of the device through a specially crafted POST request. This presents significant risks for any network leveraging the affected product, as service interruption can lead to accessibility issues and potential data exposure.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database