CVE-2024-2979: Tenda F1203 openSchedWifi setSchedWifi stack-based overflow
A vulnerability classified as critical was found in Tenda F1203 2.0.1.6. This vulnerability affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258148. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2979?
CVE-2024-2979 is classified as a critical vulnerability.
How do I fix CVE-2024-2979?
To fix CVE-2024-2979, update the Tenda F1203 firmware to the latest version.
What does CVE-2024-2979 affect?
CVE-2024-2979 affects the Tenda F1203 firmware version 2.0.1.6.
What is the nature of the vulnerability in CVE-2024-2979?
CVE-2024-2979 involves a stack-based buffer overflow due to improper handling of the schedStartTime/schedEndTime parameters.
What are the potential consequences of exploiting CVE-2024-2979?
Exploiting CVE-2024-2979 could allow an attacker to execute arbitrary code on the affected device.