PT-2024-8941 · Tenda · Tenda Fh1202+3

·

CVE-2024-12002

·

Published

2024-10-22

·

Updated

2024-12-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Tenda FH451 versions up to 20241129 Tenda FH1201 versions up to 20241129 Tenda FH1202 versions up to 20241129 Tenda FH1206 versions up to 20241129
Description: The issue is related to a null pointer dereference error in the websReadEvent() function of the affected Tenda router models. This can be exploited by sending specially crafted packets, potentially allowing a remote attacker to cause a denial of service. The manipulation of the Content-Length argument leads to this null pointer dereference. The attack can be launched remotely.
Recommendations: For Tenda FH451 versions up to 20241129, update the firmware immediately and restrict remote access to the /goform/GetIPTV endpoint. For Tenda FH1201 versions up to 20241129, update the firmware immediately and restrict remote access to the /goform/GetIPTV endpoint. For Tenda FH1202 versions up to 20241129, update the firmware immediately and restrict remote access to the /goform/GetIPTV endpoint. For Tenda FH1206 versions up to 20241129, update the firmware immediately and restrict remote access to the /goform/GetIPTV endpoint. As a temporary workaround, consider disabling the websReadEvent() function until a patch is available. Restrict access to the /goform/GetIPTV endpoint to minimize the risk of exploitation. Avoid using the Content-Length argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10618
CVE-2024-12002

Affected Products

Tenda Fh1201
Tenda Fh1202
Tenda Fh1206
Tenda Fh451