Tenda Fh1202 vulnerabilities

31 known vulnerabilities affecting tenda/fh1202.

Total CVEs
31
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2025-2990MEDIUMCVSS 6.9v1.2.0.14(408)2025-03-31
CVE-2025-2990 [MEDIUM] CWE-266 CVE-2025-2990: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue a A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/AdvSetWrlGstset of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may
cvelistv5nvd
CVE-2025-2996MEDIUMCVSS 6.9v1.2.0.14(408)2025-03-31
CVE-2025-2996 [MEDIUM] CWE-266 CVE-2025-2996: A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affec A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affects some unknown processing of the file /goform/SysToolDDNS of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-12002MEDIUMCVSS 5.3v202411292024-11-30
CVE-2024-12002 [MEDIUM] CWE-404 CVE-2024-12002: A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed t
cvelistv5nvd
CVE-2024-2982HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2982 [MEDIUM] CWE-77 CVE-2024-2982: A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerab
cvelistv5nvd
CVE-2024-2986HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2986 [HIGH] CWE-121 CVE-2024-2986: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue a A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The a
cvelistv5nvd
CVE-2024-2987HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2987 [HIGH] CWE-121 CVE-2024-2987: A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is the A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-2981HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2981 [HIGH] CWE-121 CVE-2024-2981: A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). Affected A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public a
cvelistv5nvd
CVE-2024-2983HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2983 [HIGH] CWE-121 CVE-2024-2983: A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this issue is the function formSetClientState of the file /goform/SetClientState. The manipulation of the argument deviceId/limitSpeed/limitSpeedUp leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to th
cvelistv5nvd
CVE-2024-2985HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2985 [HIGH] CWE-121 CVE-2024-2985: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vuln A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may b
cvelistv5nvd
CVE-2024-2984HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2984 [HIGH] CWE-121 CVE-2024-2984: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been classified as critical. This af A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been classified as critical. This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The id
cvelistv5nvd
CVE-2024-2980HIGHCVSS 8.8v1.2.0.14(408)2024-03-27
CVE-2024-2980 [HIGH] CWE-121 CVE-2024-2980: A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Thi A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used
cvelistv5nvd
Tenda Fh1202 vulnerabilities | cvebase