PT-2024-23083 · Tenda · Tenda Fh1202

Wxhwxhwxh_Tutu

·

Published

2024-03-27

·

Updated

2025-01-14

·

CVE-2024-2985

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda FH1202 version 1.2.0.14(408)
Description A critical issue affects the function formQuickIndex of the file /goform/QuickIndex, where the manipulation of the PPPOEPassword argument leads to a stack-based buffer overflow. This can be initiated remotely, and an exploit has been publicly disclosed, making it potentially usable. The vendor was contacted about this issue but did not respond.
Recommendations For Tenda FH1202 version 1.2.0.14(408), as a temporary workaround, consider disabling the formQuickIndex function until a patch is available. Restrict access to the /goform/QuickIndex file to minimize the risk of exploitation. Avoid using the PPPOEPassword argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-2985

Affected Products

Tenda Fh1202