PT-2024-2459 · Tenda · Tenda Fh1202

Published

2024-03-29

·

Updated

2024-07-03

·

CVE-2024-30637

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda F1202 version 1.2.0.20(408)
Description The issue is related to the formWriteFacMac function, specifically the /goform/WriteFacMac API endpoint, where a command injection vulnerability exists due to inadequate data cleaning at the management level. This allows a remote attacker to execute arbitrary commands. The vulnerability is associated with the mac parameter.
Recommendations For Tenda F1202 version 1.2.0.20(408), consider disabling the formWriteFacMac function or restricting access to the /goform/WriteFacMac API endpoint until a patch is available. Avoid using the mac parameter in the affected API endpoint to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-02437
CVE-2024-30637

Affected Products

Tenda Fh1202