CVE-2024-2980: Tenda FH1202 execCommand formexeCommand stack-based overflow
A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258149 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2980?
CVE-2024-2980 is classified as a critical vulnerability.
How do I fix CVE-2024-2980?
To fix CVE-2024-2980, update the Tenda FH1202 firmware to the latest version provided by Tenda.
What type of vulnerability is CVE-2024-2980?
CVE-2024-2980 is a stack-based buffer overflow vulnerability.
Which device is affected by CVE-2024-2980?
CVE-2024-2980 affects the Tenda FH1202 firmware version 1.2.0.14(408).
What can happen if CVE-2024-2980 is exploited?
Exploitation of CVE-2024-2980 could allow an attacker to execute arbitrary commands on the device.