Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8f64-5gvc-rwm8

Опубликовано: 30 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 31%
0.00115
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-404
CWE-476

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 года назад

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость функции websReadEvent() микропрограммного обеспечения маршрутизаторов Tenda FH451, Tenda FH1201, Tenda FH1202 и Tenda FH1206, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 31%
0.00115
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-404
CWE-476