CVE-2024-29671
nicheBuffer Overflow in NEXTU FLATA AX1500 Router Allows Unauthenticated RCE
CVE-2024-29671 is a buffer overflow (CWE-120) in the POST request handler of the web interface on the NEXTU FLATA AX1500 router running firmware 1.0.2. Because the flaw is reachable over the network without authentication or user interaction (CVSS 3.1 AV:N/PR:N), an attacker who can send a crafted POST request to the router's HTTP service can trigger the overflow. Successful exploitation allows arbitrary code execution on the device, giving the attacker full control of the router and a foothold for traffic interception or attacks on connected devices. Only NEXTU FLATA AX1500 units running the affected firmware are impacted, with remote exposure limited to routers whose management interface is reachable from the WAN. There are no reports of in-the-wild exploitation and no known public proof-of-concept, but the 20.9% EPSS score (97th percentile) indicates an elevated likelihood of exploitation within the next 30 days.
What to do: Upgrade the FLATA AX1500 to the latest firmware from NEXTU as soon as a fixed release is published (any version later than 1.0.2), and check vendor support channels for the patch. Until patched, disable or restrict the router's WAN-facing web management so the POST endpoint is only reachable from the local network. Since no public PoC exists, prioritize internet-exposed units but monitor for updated advisories given the elevated EPSS score.
| NEXTU FLATA AX1500 Router | 1.0.2 (per advisory; other versions not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.