CVE-2024-30636: Medium severity tendacn f1202 firmware vulnerability
Published Mar 29, 2024
·Updated
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.
Affected Software
3 affected components
Tenda F1202
All of the following
Tenda F1202 Firmware=1.2.0.20\(408\)
Tenda F1202
Event History
Mar 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30636?
CVE-2024-30636 has been classified as a high severity vulnerability due to its potential for exploitation through stack overflow.
2
How do I fix CVE-2024-30636?
To mitigate CVE-2024-30636, update the Tenda F1202 firmware to the latest version where the vulnerability has been patched.
3
What are the potential impacts of CVE-2024-30636?
Exploitation of CVE-2024-30636 may lead to remote code execution or a denial of service due to the stack overflow.
4
Which products are affected by CVE-2024-30636?
CVE-2024-30636 specifically affects the Tenda F1202 with firmware version v1.2.0.20(408).
5
What is the exploit mechanism for CVE-2024-30636?
CVE-2024-30636 can be exploited by sending specially crafted data to the PPPOEPassword parameter in the formQuickIndex function.