ID

VAR-202404-1760


CVE

CVE-2024-32283


TITLE

Shenzhen Tenda Technology Co.,Ltd.  of  fh1203  Command injection vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2024-020814

DESCRIPTION

Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter. Shenzhen Tenda Technology Co.,Ltd. of fh1203 Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda FH1203 is a dual-band wireless router released by China's Tenda Group, primarily used for home network coverage. This vulnerability stems from the cmdinput parameter of the formexeCommand method failing to properly filter special characters and commands when constructing commands. An attacker could exploit this vulnerability to execute arbitrary commands

Trust: 2.16

sources: NVD: CVE-2024-32283 // JVNDB: JVNDB-2024-020814 // CNVD: CNVD-2025-17021

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-17021

AFFECTED PRODUCTS

vendor:tendamodel:fh1203scope:eqversion:2.0.1.6

Trust: 1.6

vendor:tendamodel:fh1203scope:eqversion: -

Trust: 0.8

vendor:tendamodel:fh1203scope: - version: -

Trust: 0.8

vendor:tendamodel:fh1203scope:eqversion:fh1203 firmware 2.0.1.6

Trust: 0.8

sources: CNVD: CNVD-2025-17021 // JVNDB: JVNDB-2024-020814 // NVD: CVE-2024-32283

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-32283
value: HIGH

Trust: 1.0

OTHER: JVNDB-2024-020814
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-17021
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-17021
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2024-32283
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.3
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2024-020814
baseSeverity: HIGH
baseScore: 7.3
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-17021 // JVNDB: JVNDB-2024-020814 // NVD: CVE-2024-32283

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

problemtype:Command injection (CWE-77) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-020814 // NVD: CVE-2024-32283

PATCH

title:Patch for Tenda FH1203 Command Injection Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/713081

Trust: 0.6

sources: CNVD: CNVD-2025-17021

EXTERNAL IDS

db:NVDid:CVE-2024-32283

Trust: 3.2

db:JVNDBid:JVNDB-2024-020814

Trust: 0.8

db:CNVDid:CNVD-2025-17021

Trust: 0.6

sources: CNVD: CNVD-2025-17021 // JVNDB: JVNDB-2024-020814 // NVD: CVE-2024-32283

REFERENCES

url:https://github.com/abcdefg-png/iot-vulnerable/blob/main/tenda/fh/fh1203/formexecommand_cmdi.md

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2024-32283

Trust: 0.8

sources: CNVD: CNVD-2025-17021 // JVNDB: JVNDB-2024-020814 // NVD: CVE-2024-32283

SOURCES

db:CNVDid:CNVD-2025-17021
db:JVNDBid:JVNDB-2024-020814
db:NVDid:CVE-2024-32283

LAST UPDATE DATE

2025-07-30T23:04:35.781000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-17021date:2025-07-29T00:00:00
db:JVNDBid:JVNDB-2024-020814date:2025-03-24T09:15:00
db:NVDid:CVE-2024-32283date:2025-03-17T14:55:37.623

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-17021date:2025-07-29T00:00:00
db:JVNDBid:JVNDB-2024-020814date:2025-03-24T00:00:00
db:NVDid:CVE-2024-32283date:2024-04-17T14:15:08.683