cbcvebase.

Tenda Fh1202 Firmware vulnerabilities

63 known vulnerabilities affecting tenda/fh1202_firmware.

Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH25MEDIUM19

Vulnerabilities

Page 3 of 4
CVE-2023-38932P3CRITICALCVSS 9.8v1.2.0.92023-08-07
CVE-2023-38932 [CRITICAL] CWE-787 CVE-2023-38932: Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter in the SafeEmailFilter function.
nvd
CVE-2024-30591P3HIGHCVSS 8.8v1.2.0.14\(408\)2024-03-28
CVE-2024-30591 [HIGH] CWE-121 CVE-2024-30591: Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the savePare Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
nvd
CVE-2024-30583P3HIGHCVSS 8.0v1.2.0.14\(408\)2024-03-28
CVE-2024-30583 [HIGH] CWE-121 CVE-2024-30583: Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.
nvd
CVE-2024-30592P3HIGHCVSS 8.0v1.2.0.14\(408\)2024-03-28
CVE-2024-30592 [HIGH] CWE-121 CVE-2024-30592: Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddr Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.
nvd
CVE-2025-2993P3MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2993 [MEDIUM] CWE-266 CVE-2025-2993: A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Aff A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file /default.cfg. The manipulation of the argument these leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-32282P3MEDIUMCVSS 6.3v1.2.0.14\(408\)2024-04-17
CVE-2024-32282 [MEDIUM] CWE-77 CVE-2024-32282: Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeComma Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
nvd
CVE-2024-32302P3MEDIUMCVSS 6.3v1.2.0.14\(408\)2024-04-17
CVE-2024-32302 [MEDIUM] CWE-787 CVE-2024-32302: Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
nvd
CVE-2024-12002P3MEDIUMCVSS 6.5v1.2.0.9v1.2.0.14\(408\)+1 more2024-11-30
CVE-2024-12002 [MEDIUM] CWE-404 CVE-2024-12002: A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed t
nvd
CVE-2025-2992P3MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2992 [MEDIUM] CWE-266 CVE-2025-2992: A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vul A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unknown functionality of the file /goform/AdvSetWrlsafeset of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public
nvd
CVE-2025-2994P4MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2994 [MEDIUM] CWE-266 CVE-2025-2994: A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This aff A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be us
nvd
CVE-2025-2991P3MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2991 [MEDIUM] CWE-266 CVE-2025-2991: A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmacfilter of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2025-2995P4MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2995 [MEDIUM] CWE-266 CVE-2025-2995: A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulner A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects unknown code of the file /goform/SysToolChangePwd of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may b
nvd
CVE-2025-3236P4MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-04-04
CVE-2025-3236 [MEDIUM] CWE-266 CVE-2025-3236: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vuln A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/VirSerDMZ of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be use
nvd
CVE-2025-2990P4MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2990 [MEDIUM] CWE-266 CVE-2025-2990: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue a A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/AdvSetWrlGstset of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may
nvd
CVE-2025-2989P4MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2989 [MEDIUM] CWE-266 CVE-2025-2989: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vuln A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/AdvSetWrl of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be use
nvd
CVE-2025-2996P4MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-03-31
CVE-2025-2996 [MEDIUM] CWE-266 CVE-2025-2996: A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affec A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. This issue affects some unknown processing of the file /goform/SysToolDDNS of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-3237P4MEDIUMCVSS 5.3v1.2.0.14\(408\)2025-04-04
CVE-2025-3237 [MEDIUM] CWE-266 CVE-2025-3237: A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue a A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/wrlwpsset. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-30594P4MEDIUMCVSS 6.5v1.2.0.14\(408\)2024-03-28
CVE-2024-30594 [MEDIUM] CWE-121 CVE-2024-30594: Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the add Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.
nvd
CVE-2024-30590P4MEDIUMCVSS 6.5v1.2.0.14\(408\)2024-03-28
CVE-2024-30590 [MEDIUM] CWE-121 CVE-2024-30590: Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
nvd
CVE-2024-30585P4MEDIUMCVSS 6.5v1.2.0.14\(408\)2024-03-28
CVE-2024-30585 [MEDIUM] CWE-121 CVE-2024-30585: Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the save Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.
nvd
Tenda Fh1202 Firmware vulnerabilities | cvebase