CVE-2024-42978: OS Command Injection
Published Aug 15, 2024
·Updated
An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.
Affected Software
2 affected components
All of the following
Tenda Fh1206 Firmware=v02.03.01.35
Tenda FH1206
Event History
Aug 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42978?
CVE-2024-42978 has been classified as a critical vulnerability due to its ability to allow arbitrary command execution.
2
How do I fix CVE-2024-42978?
To address CVE-2024-42978, update the Tenda FH1206 firmware to the latest version that resolves this vulnerability.
3
Who is affected by CVE-2024-42978?
CVE-2024-42978 affects users of the Tenda FH1206 firmware version v02.03.01.35.
4
What type of attack is associated with CVE-2024-42978?
CVE-2024-42978 allows attackers to perform remote code execution through crafted HTTP requests.
5
Is there a workaround for CVE-2024-42978?
There are no known workarounds for CVE-2024-42978; applying the firmware update is the recommended solution.