Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2024-42985

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42982

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42981

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42980

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42978

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.
Attacker Value
Unknown

CVE-2024-42977

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42976

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-42969

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Attacker Value
Unknown

CVE-2024-7707

Disclosure Date: August 13, 2024 (last updated August 23, 2024)
A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.