Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50526 | A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Tue, 10 Dec 2024 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda fh1201 Tenda fh1201 Firmware Tenda fh1202 Tenda fh1202 Firmware Tenda fh1206 Tenda fh1206 Firmware Tenda fh451 Tenda fh451 Firmware |
|
| CPEs | cpe:2.3:h:tenda:fh1201:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:fh1202:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:fh1206:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:fh451:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1201_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1201_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1206_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:* cpe:2.3:o:tenda:fh451_firmware:1.0.0.5:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh451_firmware:1.0.0.7:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh451_firmware:1.0.0.9:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda fh1201 Tenda fh1201 Firmware Tenda fh1202 Tenda fh1202 Firmware Tenda fh1206 Tenda fh1206 Firmware Tenda fh451 Tenda fh451 Firmware |
Mon, 02 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 30 Nov 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Tenda FH451/FH1201/FH1202/FH1206 GetIPTV websReadEvent null pointer dereference | |
| Weaknesses | CWE-404 CWE-476 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-12-02T15:54:21.033Z
Reserved: 2024-11-29T15:49:13.514Z
Link: CVE-2024-12002
Updated: 2024-12-02T15:54:16.045Z
Status : Analyzed
Published: 2024-11-30T13:15:04.610
Modified: 2024-12-10T23:21:19.827
Link: CVE-2024-12002
No data.
OpenCVE Enrichment
No data.
EUVD