cbcvebase.

Tenda Fh1201 Firmware vulnerabilities

25 known vulnerabilities affecting tenda/fh1201_firmware.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH23MEDIUM1

Vulnerabilities

Page 2 of 2
CVE-2024-42955P3HIGHCVSS 7.5v1.2.0.14\(408\)2024-08-15
CVE-2024-42955 [HIGH] CWE-787 CVE-2024-42955: Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in th Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2024-42941P3HIGHCVSS 7.5v1.2.0.14\(408\)2024-08-15
CVE-2024-42941 [HIGH] CWE-787 CVE-2024-42941: Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2024-42951P3HIGHCVSS 7.5v1.2.0.14\(408\)2024-08-15
CVE-2024-42951 [HIGH] CWE-787 CVE-2024-42951: Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parame Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2024-42950P3HIGHCVSS 7.5v1.2.0.14\(408\)2024-08-15
CVE-2024-42950 [HIGH] CWE-787 CVE-2024-42950: Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
nvd
CVE-2024-12002P3MEDIUMCVSS 6.5v1.2.0.8\(8155\)v1.2.0.14\(408\)_en2024-11-30
CVE-2024-12002 [MEDIUM] CWE-404 CVE-2024-12002: A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed t
nvd