CVE-2024-2980

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 27, 2024
Updated: Jan 14, 2025
CWE ID 79

Summary

CVE-2024-2980 is a newly disclosed critical vulnerability that affects the Tenda FH1202 1.2.0.14(408) firmware. The issue lies in the function formexeCommand within the /goform/execCommand file. Manipulation of the argument cmdinput results in a stack-based buffer overflow, enabling attackers to execute arbitrary code remotely. The vulnerability has been publicly disclosed, and there is evidence of exploitation in the wild. The identifier VDB-258149 has been assigned to this vulnerability. Despite early notification, the vendor has not responded to address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share