PT-2025-17539 · Nextu · Nextu Fleta Ax1500 Wifi6 Router

Published

2025-04-22

·

Updated

2025-04-24

·

CVE-2024-46546

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions NEXTU FLETA AX1500 WIFI6 Router version 1.0.3
Description A stack overflow vulnerability was discovered, allowing attackers to cause a Denial of Service (DoS) via a crafted POST request. The issue is related to the url parameter at the "/boafrm/formFilter" API endpoint.
Recommendations For NEXTU FLETA AX1500 WIFI6 Router version 1.0.3, consider restricting access to the "/boafrm/formFilter" API endpoint to minimize the risk of exploitation. Avoid using the url parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-46546

Affected Products

Nextu Fleta Ax1500 Wifi6 Router