PT-2024-30220 · Tenda · Tenda Fh1201

Published

2024-08-15

·

Updated

2024-08-19

·

CVE-2024-42949

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda FH1201 version 1.2.0.14
Description The issue is related to a stack overflow via the qos parameter in the fromqossetting function, allowing attackers to cause a Denial of Service (DoS) via a crafted POST request to the affected API endpoint.
Recommendations For Tenda FH1201 version 1.2.0.14, consider disabling the fromqossetting function or restricting access to the qos parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-42949

Affected Products

Tenda Fh1201