CVE-2024-29671
CRITICALNEXTU FLATA AX1500 Router <1.0.2 - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-29671. PoCs published by laskdjlaskdj12.
AI-analyzed exploit summary This PoC exploits a stack overflow vulnerability in the NEXTU FLATA AX1500 router's Boa web server via a maliciously crafted POST request to /boafrm/formStaticDHCP, allowing remote code execution (RCE) as root.
Description
Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.
Exploits (1)
nomisec
WORKING POC
1 stars
by laskdjlaskdj12 · poc
https://github.com/laskdjlaskdj12/CVE-2024-29671-POC
This PoC exploits a stack overflow vulnerability in the NEXTU FLATA AX1500 router's Boa web server via a maliciously crafted POST request to /boafrm/formStaticDHCP, allowing remote code execution (RCE) as root.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
NEXTU FLATA AX1500 Router firmware v1.0.2 (Boa web server)
No auth needed
Prerequisites:
Network access to the router's web interface · Boa web server running on the target
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Various Sources
https://github.com/laskdjlaskdj12/CVE-2024-29671-POC
Scores
CVSS v3
9.8
EPSS
0.2091
EPSS Percentile
97.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-120
Status
published
Published
Dec 16, 2024
Tracked Since
Feb 18, 2026