CVE-2024-12002
MEDIUMDescription
A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Is your site exposed to CVE-2024-12002?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tenda | fh451_firmware |
| tenda | fh451_firmware |
| tenda | fh451_firmware |
| tenda | fh451 |
| tenda | fh1201_firmware |
| tenda | fh1201_firmware |
| tenda | fh1201 |
| tenda | fh1202_firmware |
| tenda | fh1202_firmware |
| tenda | fh1202_firmware |
| tenda | fh1202 |
| tenda | fh1206_firmware |
| tenda | fh1206 |
References
Frequently Asked Questions
What is CVE-2024-12002? +
How severe is CVE-2024-12002? +
What products are affected by CVE-2024-12002? +
How do I check if I'm vulnerable to CVE-2024-12002? +
Related Vulnerabilities
Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Integrity …
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon …
A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when …
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto of the file rt-thread/components/lwp/lwp_syscall.c. …
In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect Remove …