A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
2024-11-30T13:15:04.610
2024-12-10T23:21:19.827
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tenda | fh451_firmware | 1.0.0.5 | Yes |
Operating System | tenda | fh451_firmware | 1.0.0.7 | Yes |
Operating System | tenda | fh451_firmware | 1.0.0.9 | Yes |
Hardware | tenda | fh451 | - | No |
Operating System | tenda | fh1201_firmware | 1.2.0.8\(8155\) | Yes |
Operating System | tenda | fh1201_firmware | 1.2.0.14\(408\)_en | Yes |
Hardware | tenda | fh1201 | - | No |
Operating System | tenda | fh1202_firmware | 1.2.0.9 | Yes |
Operating System | tenda | fh1202_firmware | 1.2.0.14\(408\) | Yes |
Operating System | tenda | fh1202_firmware | 1.2.0.14\(408\)_en | Yes |
Hardware | tenda | fh1202 | - | No |
Operating System | tenda | fh1206_firmware | 1.2.0.8\(8155\) | Yes |
Hardware | tenda | fh1206 | - | No |