Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12002


A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.


Published

2024-11-30T13:15:04.610

Last Modified

2024-12-10T23:21:19.827

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-404
    CWE-476
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tenda fh451_firmware 1.0.0.5 Yes
Operating System tenda fh451_firmware 1.0.0.7 Yes
Operating System tenda fh451_firmware 1.0.0.9 Yes
Hardware tenda fh451 - No
Operating System tenda fh1201_firmware 1.2.0.8\(8155\) Yes
Operating System tenda fh1201_firmware 1.2.0.14\(408\)_en Yes
Hardware tenda fh1201 - No
Operating System tenda fh1202_firmware 1.2.0.9 Yes
Operating System tenda fh1202_firmware 1.2.0.14\(408\) Yes
Operating System tenda fh1202_firmware 1.2.0.14\(408\)_en Yes
Hardware tenda fh1202 - No
Operating System tenda fh1206_firmware 1.2.0.8\(8155\) Yes
Hardware tenda fh1206 - No

References