ID

VAR-202403-1114


CVE

CVE-2024-30591


TITLE

Tenda FH1202 time parameter buffer overflow vulnerability

Trust: 0.6

sources: CNVD: CNVD-2024-36922

DESCRIPTION

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function. Tenda FH1202 is a wireless router from China's Tenda company. The vulnerability is caused by the time parameter of the saveParentControlInfo method failing to correctly verify the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service

Trust: 1.44

sources: NVD: CVE-2024-30591 // CNVD: CNVD-2024-36922

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-36922

AFFECTED PRODUCTS

vendor:tendamodel:fh1202scope:eqversion:v1.2.0.14(408)

Trust: 0.6

sources: CNVD: CNVD-2024-36922

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-30591
value: HIGH

Trust: 1.0

CNVD: CNVD-2024-36922
value: HIGH

Trust: 0.6

CNVD: CNVD-2024-36922
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-30591
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2024-36922 // NVD: CVE-2024-30591

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

sources: NVD: CVE-2024-30591

PATCH

title:Patch for Tenda FH1202 time parameter buffer overflow vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/585421

Trust: 0.6

sources: CNVD: CNVD-2024-36922

EXTERNAL IDS

db:NVDid:CVE-2024-30591

Trust: 1.6

db:CNVDid:CNVD-2024-36922

Trust: 0.6

sources: CNVD: CNVD-2024-36922 // NVD: CVE-2024-30591

REFERENCES

url:https://github.com/abcdefg-png/iot-vulnerable/blob/main/tenda/fh/fh1202/saveparentcontrolinfo_time.md

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2024-30591

Trust: 0.6

sources: CNVD: CNVD-2024-36922 // NVD: CVE-2024-30591

SOURCES

db:CNVDid:CNVD-2024-36922
db:NVDid:CVE-2024-30591

LAST UPDATE DATE

2024-08-31T22:57:44.095000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-36922date:2024-08-30T00:00:00
db:NVDid:CVE-2024-30591date:2024-08-28T18:35:14.280

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-36922date:2024-08-30T00:00:00
db:NVDid:CVE-2024-30591date:2024-03-28T14:15:15.390