Stack-based Buffer Overflow Vulnerability in Tenda FH1206 HTTP POST Request Handler
CVE-2024-7707

9.8CRITICAL

Key Information:

Vendor
Tenda
Vendor
CVE Published:
13 August 2024

Summary

A stack-based buffer overflow vulnerability has been identified in Tenda's FH1206 router, specifically within the formSafeEmailFilter function located in the HTTP POST Request Handler. This vulnerability arises from improper handling of user input in the 'page' argument, enabling attackers to execute remote code. Due to the nature of the flaw, it can be exploited over the network, posing significant risks to users of the affected firmware version (02.03.01.35). Despite prior communication efforts with Tenda regarding this issue, the company has not provided a response or patch, increasing the urgency for users to take precautions.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.