Stack Overflow Vulnerability in Tenda FH1206 v02.03.01.35 Allows DoS via POST Request
CVE-2024-42985

7.5HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
15 August 2024

Summary

The Tenda FH1206, specifically version 02.03.01.35, is impacted by a vulnerability that allows for a stack overflow through improper handling of the page parameter within the fromNatlimit function. This security flaw can be exploited by attackers to perform a Denial of Service (DoS) attack, disrupting the normal operation of the device through a specially crafted POST request. This presents significant risks for any network leveraging the affected product, as service interruption can lead to accessibility issues and potential data exposure.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.