CVE-2024-7707: Tenda FH1206 HTTP POST Request SafeEmailFilter formSafeEmailFilter stack-based overflow
A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7707?
CVE-2024-7707 is classified as a critical severity vulnerability.
How do I fix CVE-2024-7707?
To fix CVE-2024-7707, upgrade the Tenda FH1206 firmware to a version that is not affected by this vulnerability.
What component is affected by CVE-2024-7707?
CVE-2024-7707 affects the HTTP POST Request Handler in the function formSafeEmailFilter.
What is the impact of CVE-2024-7707 on Tenda FH1206?
CVE-2024-7707 can lead to stack-based buffer overflow vulnerabilities in Tenda FH1206 devices.
Is the Tenda FH1206 vulnerable to CVE-2024-7707 by default?
Yes, Tenda FH1206 with firmware version 02.03.01.35 is vulnerable to CVE-2024-7707.