cbcvebase.

Tenda Fh1202 Firmware vulnerabilities

63 known vulnerabilities affecting tenda/fh1202_firmware.

Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH25MEDIUM19

Vulnerabilities

Page 1 of 4
CVE-2026-3808P2HIGHCVSS 8.8v1.2.0.14\(408\)2026-03-09
CVE-2026-3808 [HIGH] CWE-119 CVE-2026-3808: A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function for A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a manipulation of the argument webSiteId results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
nvd
CVE-2024-2982P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2982 [HIGH] CWE-77 CVE-2024-2982: A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerabil
nvd
CVE-2024-2980P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2980 [HIGH] CWE-121 CVE-2024-2980: A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Thi A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used
nvd
CVE-2024-2986P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2986 [HIGH] CWE-121 CVE-2024-2986: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue a A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The a
nvd
CVE-2026-7034P2HIGHCVSS 8.8v1.2.0.14\(408\)2026-04-26
CVE-2026-7034 [HIGH] CWE-119 CVE-2026-7034: A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlE A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Performing a manipulation of the argument Go results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.
nvd
CVE-2024-2983P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2983 [HIGH] CWE-121 CVE-2024-2983: A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this issue is the function formSetClientState of the file /goform/SetClientState. The manipulation of the argument deviceId/limitSpeed/limitSpeedUp leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to th
nvd
CVE-2024-2985P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2985 [HIGH] CWE-121 CVE-2024-2985: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vuln A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may b
nvd
CVE-2024-2981P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2981 [HIGH] CWE-121 CVE-2024-2981: A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). Affected A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public a
nvd
CVE-2024-2984P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2984 [HIGH] CWE-121 CVE-2024-2984: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been classified as critical. This af A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been classified as critical. This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The id
nvd
CVE-2026-3811P2HIGHCVSS 8.8v1.2.0.14\(408\)2026-03-09
CVE-2026-3811 [HIGH] CWE-119 CVE-2026-3811: A vulnerability was found in Tenda FH1202 1.2.0.14(408). This impacts the function fromP2pListFilter A vulnerability was found in Tenda FH1202 1.2.0.14(408). This impacts the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
nvd
CVE-2026-3807P2HIGHCVSS 8.8v1.2.0.14\(408\)2026-03-09
CVE-2026-3807 [HIGH] CWE-119 CVE-2026-3807: A security vulnerability has been detected in Tenda FH1202 1.2.0.14(408). Impacted is the function f A security vulnerability has been detected in Tenda FH1202 1.2.0.14(408). Impacted is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Such manipulation of the argument mit_ssid/mit_ssid_index leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-7035P2HIGHCVSS 8.8v1.2.0.14\(408\)2026-04-26
CVE-2026-7035 [HIGH] CWE-119 CVE-2026-7035: A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. Executing a manipulation of the argument Go can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2026-3810P2HIGHCVSS 8.8v1.2.0.14\(408\)2026-03-09
CVE-2026-3810 [HIGH] CWE-119 CVE-2026-3810: A vulnerability has been found in Tenda FH1202 1.2.0.14(408). This affects the function fromDhcpList A vulnerability has been found in Tenda FH1202 1.2.0.14(408). This affects the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-2987P2HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-27
CVE-2024-2987 [HIGH] CWE-121 CVE-2024-2987: A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is the A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7532P2HIGHCVSS 8.8v1.2.0.14\(408\)2025-07-13
CVE-2025-7532 [HIGH] CWE-119 CVE-2025-7532: A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulner A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public
nvd
CVE-2025-7531P2HIGHCVSS 8.8v1.2.0.14\(408\)2025-07-13
CVE-2025-7531 [HIGH] CWE-119 CVE-2025-7531: A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This aff A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2025-5978P2HIGHCVSS 8.8v1.2.0.14\(408\)2025-06-10
CVE-2025-5978 [HIGH] CWE-119 CVE-2025-5978: A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7530P2HIGHCVSS 8.8v1.2.0.14\(408\)2025-07-13
CVE-2025-7530 [HIGH] CWE-119 CVE-2025-7530: A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Aff A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of the argument Username leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may
nvd
CVE-2025-7527P2HIGHCVSS 8.8v1.2.0.14\(408\)2025-07-13
CVE-2025-7527 [HIGH] CWE-119 CVE-2025-7527: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue a A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects the function fromAdvSetWan of the file /goform/AdvSetWan. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-7529P2HIGHCVSS 8.8v1.2.0.14\(408\)2025-07-13
CVE-2025-7529 [HIGH] CWE-119 CVE-2025-7529: A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vul A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is the function fromNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
nvd