PT-2024-5845 · Tenda · Tenda Fh1201

Published

2024-08-15

·

Updated

2024-08-19

·

CVE-2024-42945

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda FH1201 version 1.2.0.14 (408)
Description The issue is related to a stack overflow vulnerability in the fromAddressNat function of the Tenda FH1201 router's firmware. This vulnerability can be exploited by sending a specially crafted POST request, potentially allowing a remote attacker to cause a Denial of Service (DoS). The vulnerability is associated with the page parameter in the fromAddressNat function.
Recommendations For Tenda FH1201 version 1.2.0.14 (408), consider disabling the fromAddressNat function until a patch is available to prevent exploitation via the page parameter in crafted POST requests. Restrict access to the vulnerable function to minimize the risk of a Denial of Service (DoS) attack. Avoid using the page parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-06590
CVE-2024-42945

Affected Products

Tenda Fh1201