Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2024-42980

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42979

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42978

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.
Attacker Value
Unknown

CVE-2024-42977

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42976

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42974

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42973

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42969

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42968

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-7707

Disclosure Date: August 13, 2024 (last updated August 23, 2024)
A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.