216.73.216.197

CVE-2024-12002

· Published 30/11/2024 13:15 · Modified 10/12/2024 23:21

Labels: CVE-2024-12002 2024-11-30CVE-2024-12002CWE-404CWE-476[email protected]

Essential information

Published
30/11/2024 13:15
Modified
10/12/2024 23:21
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CVSS metrics

Description

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tenda / fh451 firmware cpe:2.3:o:tenda:fh451_firmware:1.0.0.5:*:*:*:*:*:*:*
tenda / fh451 firmware cpe:2.3:o:tenda:fh451_firmware:1.0.0.7:*:*:*:*:*:*:*
tenda / fh451 firmware cpe:2.3:o:tenda:fh451_firmware:1.0.0.9:*:*:*:*:*:*:*
tenda / fh451 cpe:2.3:h:tenda:fh451:-:*:*:*:*:*:*:*
tenda / fh1201 firmware cpe:2.3:o:tenda:fh1201_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
tenda / fh1201 firmware cpe:2.3:o:tenda:fh1201_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
tenda / fh1201 cpe:2.3:h:tenda:fh1201:-:*:*:*:*:*:*:*
tenda / fh1202 firmware cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:*
tenda / fh1202 firmware cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:*
tenda / fh1202 firmware cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
tenda / fh1202 cpe:2.3:h:tenda:fh1202:-:*:*:*:*:*:*:*
tenda / fh1206 firmware cpe:2.3:o:tenda:fh1206_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
tenda / fh1206 cpe:2.3:h:tenda:fh1206:-:*:*:*:*:*:*:*

References