CVE-2024-12002

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/Kalvin2077/tenda-fh-cve Exploit Third Party Advisory
https://vuldb.com/?ctiid.286417 Permissions Required VDB Entry
https://vuldb.com/?id.286417 Third Party Advisory VDB Entry
https://vuldb.com/?submit.453974 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:tenda:fh451_firmware:1.0.0.5:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh451_firmware:1.0.0.7:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh451_firmware:1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh451:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:tenda:fh1201_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1201_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1201:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1202:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tenda:fh1206_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1206:-:*:*:*:*:*:*:*

History

10 Dec 2024, 23:21

Type Values Removed Values Added
First Time Tenda fh451 Firmware
Tenda fh451
Tenda fh1201 Firmware
Tenda fh1201
Tenda
Tenda fh1202
Tenda fh1206 Firmware
Tenda fh1202 Firmware
Tenda fh1206
References () https://github.com/Kalvin2077/tenda-fh-cve - () https://github.com/Kalvin2077/tenda-fh-cve - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.286417 - () https://vuldb.com/?ctiid.286417 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.286417 - () https://vuldb.com/?id.286417 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.453974 - () https://vuldb.com/?submit.453974 - Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
CPE cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1201_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1206_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh451_firmware:1.0.0.7:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1206:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh451_firmware:1.0.0.5:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh451_firmware:1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1201:-:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh451:-:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh1202:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1201_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:*

Information

Published : 2024-11-30 13:15

Updated : 2024-12-10 23:21


NVD link : CVE-2024-12002

Mitre link : CVE-2024-12002

CVE.ORG link : CVE-2024-12002


JSON object : View

Products Affected

tenda

  • fh1206_firmware
  • fh1201
  • fh1202
  • fh451
  • fh1201_firmware
  • fh451_firmware
  • fh1206
  • fh1202_firmware
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-476

NULL Pointer Dereference