PT-2024-23104 · Tenda · Tenda F1203

Wxhwxhwxh_Tu

·

Published

2024-03-27

·

Updated

2025-01-15

·

CVE-2024-2988

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda FH1203 version 2.0.1.6
Description A critical vulnerability was found in the function fromSetRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument entrys leads to a stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations For Tenda FH1203 version 2.0.1.6, as a temporary workaround, consider disabling the fromSetRouteStatic function until a patch is available. Restrict access to the /goform/fromRouteStatic file to minimize the risk of exploitation. Avoid using the argument entrys in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-2988

Affected Products

Tenda F1203