VYPR
Medium severity4.3NVD Advisory· Published Nov 30, 2024· Updated Jun 17, 2026

CVE-2024-12002

CVE-2024-12002

Description

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17
  • cpe:2.3:o:tenda:fh1201_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:tenda:fh1201_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
    • cpe:2.3:o:tenda:fh1201_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
  • cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:*
    • cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\)_en:*:*:*:*:*:*:*
    • cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:*
  • cpe:2.3:o:tenda:fh1206_firmware:1.2.0.8\(8155\):*:*:*:*:*:*:*
  • cpe:2.3:o:tenda:fh451_firmware:1.0.0.5:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:tenda:fh451_firmware:1.0.0.5:*:*:*:*:*:*:*
    • cpe:2.3:o:tenda:fh451_firmware:1.0.0.7:*:*:*:*:*:*:*
    • cpe:2.3:o:tenda:fh451_firmware:1.0.0.9:*:*:*:*:*:*:*
  • Tenda/FH1201llm-fuzzy
    Range: <=20241129
  • Tenda/FH1202llm-fuzzy4 versions
    <=20241129+ 3 more
    • (no CPE)range: <=20241129
    • (no CPE)range: 20241129
    • (no CPE)range: 20241129
    • (no CPE)range: 20241129
  • Tenda/FH451llm-fuzzy2 versions
    <=20241129+ 1 more
    • (no CPE)range: <=20241129
    • (no CPE)range: 20241129
  • Tenda/FH1206llm-fuzzy
    Range: <=20241129

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.