VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202403-1111 CVE-2024-30599 Shenzhen Tenda Technology Co.,Ltd.  of  fh1203  Stack-based buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 8.8
Severity: HIGH
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function. Shenzhen Tenda Technology Co.,Ltd. of fh1203 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The vulnerability is caused by the deviceMac parameter of the addWifiMacFilter method failing to properly verify the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
VAR-202403-1112 CVE-2024-30598 Shenzhen Tenda Technology Co.,Ltd.  of  fh1203  Stack-based buffer overflow vulnerability in firmware CVSS V2: 6.1
CVSS V3: 6.5
Severity: MEDIUM
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function. Shenzhen Tenda Technology Co.,Ltd. of fh1203 A stack-based buffer overflow vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. The Tenda FH1203 is a dual-band wireless router released by China's Tenda Group, primarily used for home network coverage. This vulnerability stems from the fact that the security_5g parameter in the formWifiBasicSet method fails to properly validate the length of input data. An attacker could exploit this vulnerability to cause a denial of service
VAR-202403-1306 CVE-2024-30597 Shenzhen Tenda Technology Co.,Ltd.  of  fh1203  Stack-based buffer overflow vulnerability in firmware CVSS V2: 6.1
CVSS V3: 6.5
Severity: MEDIUM
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function. Shenzhen Tenda Technology Co.,Ltd. of fh1203 A stack-based buffer overflow vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. The Tenda FH1203 is a dual-band wireless router released by China's Tenda Group, primarily used for home network coverage. This vulnerability stems from the fact that the security parameter in the formWifiBasicSet method fails to properly validate the length of input data. An attacker could exploit this vulnerability to cause a denial of service
VAR-202403-2444 CVE-2024-30607 Shenzhen Tenda Technology Co.,Ltd.  of  fh1203  Stack-based buffer overflow vulnerability in firmware CVSS V2: 7.7
CVSS V3: 8.0
Severity: HIGH
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function. Shenzhen Tenda Technology Co.,Ltd. of fh1203 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda FH1203 is a dual-band wireless router released by China's Tenda, primarily used for home network coverage. This vulnerability stems from the failure of the deviceId parameter in the saveParentControlInfo method to properly validate the length of input data. An attacker could exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
VAR-202403-2067 CVE-2024-30606 Shenzhen Tenda Technology Co.,Ltd.  of  fh1203  Stack-based buffer overflow vulnerability in firmware CVSS V2: 7.7
CVSS V3: 8.0
Severity: HIGH
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function. Shenzhen Tenda Technology Co.,Ltd. of fh1203 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda FH1203 is a dual-band wireless router released by China's Tenda, primarily used for home network coverage. This vulnerability stems from the failure of the "page" parameter in the "fromDhcpListClient" method to properly validate the length of input data. An attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service
VAR-202403-2634 CVE-2024-30592 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 8.0
Severity: HIGH
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The vulnerability is caused by the page parameter of the fromAddressNat method failing to properly verify the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
VAR-202403-1114 CVE-2024-30591 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 8.8
Severity: HIGH
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The vulnerability is caused by the time parameter of the saveParentControlInfo method failing to correctly verify the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
VAR-202403-1698 CVE-2024-30590 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 6.1
CVSS V3: 6.5
Severity: MEDIUM
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. The Tenda FH1202 is a dual-band wireless router designed for large homes, small offices, or business/leisure areas, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is currently unavailable
VAR-202403-1307 CVE-2024-30589 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda FH1202 is a dual-band wireless router launched by Tenda, designed for large homes or small office environments, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is not currently available
VAR-202403-2073 CVE-2024-30588 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 4.0
CVSS V3: 4.3
Severity: MEDIUM
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function. Shenzhen Tenda Technology Co.,Ltd. The Tenda FH1202 is a dual-band wireless router launched by Tenda, designed for large homes or small office environments, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is not currently available
VAR-202403-1115 CVE-2024-30587 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Out-of-bounds read vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 An out-of-bounds read vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda FH1202 is a dual-band wireless router designed for large homes, small offices, or business/leisure areas, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is not currently available
VAR-202403-2635 CVE-2024-30586 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 6.1
CVSS V3: 6.5
Severity: MEDIUM
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. The Tenda FH1202 is a dual-band wireless router designed for large homes, small offices, or business/leisure areas, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is not currently available
VAR-202403-1699 CVE-2024-30585 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 6.1
CVSS V3: 6.5
Severity: MEDIUM
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. The Tenda FH1202 is a dual-band wireless router designed for large homes, small offices, or business/leisure areas, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is not currently available
VAR-202403-1308 CVE-2024-30584 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Classic buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 Firmware has a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda FH1202 is a dual-band wireless router designed for large homes, small offices, or business/leisure areas, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is not currently available
VAR-202403-2074 CVE-2024-30583 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 7.7
CVSS V3: 8.0
Severity: HIGH
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda FH1202 is a dual-band wireless router launched by Tenda, designed for large homes, small offices, or business and leisure areas, aiming to provide stable wireless network coverage and high-speed transmission. Detailed vulnerability information is not currently available
VAR-202403-2025 CVE-2023-6437 TP-LINK AX1500 Operating System Command Injection Vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3, TP-Link VX220-G2u, TP-Link VN020-G2u allows authenticated OS Command Injection.This issue affects TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3 : through 20240328. Also  the vulnerability continues in the TP-Link VX220-G2u and TP-Link VN020-G2u models due to the products not being produced and supported. TP-LINK AX1500 is a modem from China's TP-LINK company. Attackers can exploit this vulnerability to cause arbitrary command execution
VAR-202403-2070 CVE-2024-30596 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Out-of-bounds read vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 An out-of-bounds read vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The vulnerability is caused by the deviceId parameter of the formSetDeviceName method failing to properly validate the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
VAR-202403-2071 CVE-2024-30594 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 6.5
Severity: MEDIUM
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. The vulnerability is caused by the deviceMac parameter of the addWifiMacFilter method failing to properly verify the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
VAR-202403-2072 CVE-2024-30593 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Classic buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 Firmware has a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The vulnerability is caused by the deviceName parameter of the formSetDeviceName method failing to properly validate the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service
VAR-202403-1113 CVE-2024-30595 Shenzhen Tenda Technology Co.,Ltd.  of  FH1202  Stack-based buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function. Shenzhen Tenda Technology Co.,Ltd. of FH1202 A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The vulnerability is caused by the deviceId parameter of the addWifiMacFilter method failing to properly verify the length of the input data. Attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service