CVE-2024-2983

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 27, 2024
Updated: Jan 14, 2025
CWE ID 284

Summary

CVE-2024-2983 is a newly disclosed critical vulnerability affecting the Tenda FH1202 firmware version 1.2.0.14(408). The issue lies within the function formSetClientState of the SetClientState.go file, which results in a stack-based buffer overflow when the arguments deviceId/limitSpeed/limitSpeedUp are manipulated. This vulnerability can be exploited remotely, and the attack code has been made public. The identifier of this issue is VDB-258152. Despite early disclosure to the vendor, no response was received from them regarding this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share