Tenda
Tenda Fh1203 Firmware: vulnerabilidades y CVE
Tenda Fh1203 Firmware tiene 35 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses1
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-69700 | Alta (7.5) | 3.6% | — | 23 feb 2026 | Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler. |
| CVE-2025-6113 | Alta (7.4) | 1.3% | — | 16 jun 2025 | A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer… |
| CVE-2024-32311 | Media (6.5) | 0.50% | — | 17 abr 2024 | Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function. |
| CVE-2024-32299 | Alta (8.8) | 0.79% | — | 17 abr 2024 | Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function. |
| CVE-2024-32283 | Alta (7.3) | 0.88% | — | 17 abr 2024 | Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter. |
| CVE-2024-30604 | Alta (7.5) | 0.75% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function. |
| CVE-2024-30603 | Media (6.5) | 0.51% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function. |
| CVE-2024-30602 | Crítica (9.8) | 0.73% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function. |
| CVE-2024-30601 | Alta (8) | 0.70% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function. |
| CVE-2024-30600 | Alta (8) | 0.70% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function. |
| CVE-2024-30599 | Alta (8.8) | 0.70% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function. |
| CVE-2024-30598 | Media (6.5) | 0.53% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function. |
| CVE-2024-30597 | Media (6.5) | 0.53% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function. |
| CVE-2024-30607 | Alta (8) | 0.69% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function. |
| CVE-2024-30606 | Alta (8) | 0.69% | — | 28 mar 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function. |
| CVE-2024-2994 | Alta (8.8) | 1.5% | — | 27 mar 2024 | A vulnerability was found in Tenda FH1203 2.0.1.6. It has been declared as critical. Affected by this vulnerability is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the… |
| CVE-2024-2993 | Alta (8.8) | 1.6% | — | 27 mar 2024 | A vulnerability was found in Tenda FH1203 2.0.1.6. It has been classified as critical. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to… |
| CVE-2024-2992 | Alta (8.8) | 1.7% | — | 27 mar 2024 | A vulnerability was found in Tenda FH1203 2.0.1.6 and classified as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer… |
| CVE-2024-2991 | Alta (8.8) | 7.6% | — | 27 mar 2024 | A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to… |
| CVE-2024-2990 | Alta (8.8) | 1.5% | — | 27 mar 2024 | A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. This affects the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to… |
| CVE-2024-2989 | Alta (8.8) | 1.6% | — | 27 mar 2024 | A vulnerability, which was classified as critical, has been found in Tenda FH1203 2.0.1.6. Affected by this issue is the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the… |
| CVE-2024-2988 | Alta (8.8) | 1.6% | — | 27 mar 2024 | A vulnerability classified as critical was found in Tenda FH1203 2.0.1.6. Affected by this vulnerability is the function fromSetRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument entrys… |
| CVE-2023-38940 | Crítica (9.8) | 0.84% | — | 7 ago 2023 | Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function. |
| CVE-2023-38936 | Crítica (9.8) | 0.85% | — | 7 ago 2023 | Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a… |
| CVE-2023-38934 | Crítica (9.8) | 0.84% | — | 7 ago 2023 | Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function. |
| CVE-2023-38933 | Crítica (9.8) | 0.84% | — | 7 ago 2023 | Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the… |
| CVE-2023-38931 | Crítica (9.8) | 0.84% | — | 7 ago 2023 | Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to… |
| CVE-2023-37707 | Crítica (9.8) | 1.1% | — | 10 jul 2023 | Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. |
| CVE-2023-37706 | Crítica (9.8) | 1.2% | — | 10 jul 2023 | Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function. |
| CVE-2023-37705 | Crítica (9.8) | 1.2% | — | 10 jul 2023 | Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.