PT-2023-9044 · Tenda · Tenda Fh1202
Published
2023-07-13
·
Updated
2023-07-21
·
CVE-2023-37722
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda F1202 version V1.0BR V1.2.0.20(408)
Tenda FH1202 version V1.2.0.19 EN
Description
A stack overflow issue was discovered in the
fromSafeUrlFilter function, related to the page parameter. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations
For Tenda F1202 version V1.0BR V1.2.0.20(408), consider disabling the
fromSafeUrlFilter function until a patch is available.
For Tenda FH1202 version V1.2.0.19 EN, restrict access to the page parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Fh1202