PT-2024-5190 · Tenda · Tenda Fh1206

Published

2024-05-10

·

Updated

2024-08-15

·

CVE-2024-34944

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Tenda FH1206 version 1.2.0.8(8155) EN
Description: The issue is related to a stack-based buffer overflow via the list1 parameter at the "ip/goform/DhcpListClient" endpoint. This can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is associated with the fromDhcpListClient function and involves reading data beyond the buffer boundaries in memory.
Recommendations: For Tenda FH1206 version 1.2.0.8(8155) EN, consider restricting access to the "ip/goform/DhcpListClient" endpoint to minimize the risk of exploitation. Avoid using the list1 parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05746
CVE-2024-34944

Affected Products

Tenda Fh1206