PT-2024-8941 · Tenda · Tenda Fh1202+3
Kalv1N2077
·
Published
2024-10-22
·
Updated
2024-12-10
·
CVE-2024-12002
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Tenda FH451 versions up to 20241129
Tenda FH1201 versions up to 20241129
Tenda FH1202 versions up to 20241129
Tenda FH1206 versions up to 20241129
Description:
The issue is related to a null pointer dereference error in the
websReadEvent() function of the affected Tenda router models. This can be exploited by sending specially crafted packets, potentially allowing a remote attacker to cause a denial of service. The manipulation of the Content-Length argument leads to this null pointer dereference. The attack can be launched remotely.Recommendations:
For Tenda FH451 versions up to 20241129, update the firmware immediately and restrict remote access to the
/goform/GetIPTV endpoint.
For Tenda FH1201 versions up to 20241129, update the firmware immediately and restrict remote access to the /goform/GetIPTV endpoint.
For Tenda FH1202 versions up to 20241129, update the firmware immediately and restrict remote access to the /goform/GetIPTV endpoint.
For Tenda FH1206 versions up to 20241129, update the firmware immediately and restrict remote access to the /goform/GetIPTV endpoint.
As a temporary workaround, consider disabling the websReadEvent() function until a patch is available. Restrict access to the /goform/GetIPTV endpoint to minimize the risk of exploitation. Avoid using the Content-Length argument in the affected API endpoint until the issue is resolved.Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Fh1201
Tenda Fh1202
Tenda Fh1206
Tenda Fh451