Stack-based Buffer Overflow Vulnerability in Tenda FH1206 HTTP POST Request Handler
CVE-2024-7707
9.8CRITICAL
Summary
A stack-based buffer overflow vulnerability has been identified in Tenda's FH1206 router, specifically within the formSafeEmailFilter function located in the HTTP POST Request Handler. This vulnerability arises from improper handling of user input in the 'page' argument, enabling attackers to execute remote code. Due to the nature of the flaw, it can be exploited over the network, posing significant risks to users of the affected firmware version (02.03.01.35). Despite prior communication efforts with Tenda regarding this issue, the company has not provided a response or patch, increasing the urgency for users to take precautions.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database