CVE-2024-12002
CVSS V2 None
CVSS V3 None
Description
A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Overview
- CVE ID
- CVE-2024-12002
- Assigner
- VulDB
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-11-30T13:00:14.751Z
- Last Modified Date
- 2024-11-30T13:00:14.751Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://vuldb.com/?id.286417 | vdb-entry technical-description |
https://vuldb.com/?ctiid.286417 | signature permissions-required |
https://vuldb.com/?submit.453974 | third-party-advisory |
https://github.com/Kalvin2077/tenda-fh-cve | exploit |
https://www.tenda.com.cn/ | product |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-12002 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-12002 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-01 13:10:53 | Added to TrackCVE |