CVE-2024-4020: Tenda FH1206 addressNat fromAddressNat buffer overflow
A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument entrys leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261671. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4020?
CVE-2024-4020 is classified as a critical vulnerability.
What type of vulnerability is CVE-2024-4020?
CVE-2024-4020 is a buffer overflow vulnerability found in Tenda FH1206 firmware.
How can an attacker exploit CVE-2024-4020?
An attacker can exploit CVE-2024-4020 remotely by manipulating the argument entrys in the fromAddressNat function.
Which device is affected by CVE-2024-4020?
CVE-2024-4020 affects the Tenda FH1206 firmware version 1.2.0.8(8155).
How do I mitigate CVE-2024-4020?
To mitigate CVE-2024-4020, ensure that your Tenda FH1206 firmware is updated to the latest version provided by the vendor.