CVE-2024-2986

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Mar 27, 2024
Updated: Jan 14, 2025
CWE ID 338

Summary

CVE-2024-2986 is a critical vulnerability impacting the Tenda FH1202 1.2.0.14(408) firmware. The issue lies in the formSetSpeedWan function of the /goform/SetSpeedWan file. An attacker can exploit a stack-based buffer overflow by manipulating the argument speed_dir. This vulnerability can be exploited remotely, and its exploit has been disclosed to the public. The associated identifier for this vulnerability is VDB-258155. Unfortunately, vendor response to this disclosure has been unresponsive.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share