CVE-2024-2986
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Mar 27, 2024
Updated: Jan 14, 2025
CWE ID 338
Summary
CVE-2024-2986 is a critical vulnerability impacting the Tenda FH1202 1.2.0.14(408) firmware. The issue lies in the formSetSpeedWan function of the /goform/SetSpeedWan file. An attacker can exploit a stack-based buffer overflow by manipulating the argument speed_dir. This vulnerability can be exploited remotely, and its exploit has been disclosed to the public. The associated identifier for this vulnerability is VDB-258155. Unfortunately, vendor response to this disclosure has been unresponsive.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Apache Software Foundation