← Back

CVE-2024-12002

nvd nist
Published: Nov 30, 2024Modified: Dec 10, 2024

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected (9)

4 products
Fh451 Firmware
Fh1201 Firmware
Fh1202 Firmware
Fh1206 Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tenda
Version 1.0.0.5
Version 1.0.0.7
Version 1.0.0.9
Running on/withPlatform Versions
Tenda
Fh451
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tenda
Version 1.2.0.14(408)_en
Version 1.2.0.8(8155)
Running on/withPlatform Versions
Tenda
Fh1201
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tenda
Version 1.2.0.14(408)
Version 1.2.0.14(408)_en
Version 1.2.0.9
Running on/withPlatform Versions
Tenda
Fh1202
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.2.0.8(8155)
Running on/withPlatform Versions
Tenda
Fh1206
All versions

References (5)

Source: cna@vuldb.com
ExploitThird Party Advisory
Source: cna@vuldb.com
Permissions RequiredVDB Entry
Source: cna@vuldb.com
Third Party AdvisoryVDB Entry
Source: cna@vuldb.com
Third Party AdvisoryVDB Entry
Source: cna@vuldb.com
Product

Timeline

No history available yet.