Tenda
Tenda Fh1201 Firmware: vulnerabilidades y CVE
Tenda Fh1201 Firmware tiene 25 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-5046 | Alta (7.4) | 1.0% | — | 29 mar 2026 | A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component Parameter Handler. Executing a manipulation of the argument GO can lead to… |
| CVE-2026-5045 | Alta (7.4) | 1.0% | — | 29 mar 2026 | A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/WrlclientSet of the component Parameter Handler. Performing a manipulation of the argument GO… |
| CVE-2025-14994 | Alta (7.4) | 0.75% | — | 21 dic 2025 | A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request Handler. This manipulation of the argument… |
| CVE-2025-14995 | Alta (7.4) | 0.74% | — | 21 dic 2025 | A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may… |
| CVE-2025-7551 | Alta (7.4) | 1.2% | — | 14 jul 2025 | A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been declared as critical. Affected by this vulnerability is the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of the argument… |
| CVE-2025-7550 | Alta (7.4) | 0.89% | — | 13 jul 2025 | A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been classified as critical. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argument dips leads to… |
| CVE-2025-7549 | Alta (7.4) | 0.89% | — | 13 jul 2025 | A vulnerability was found in Tenda FH1201 1.2.0.14(408) and classified as critical. This issue affects the function frmL7ProtForm of the file /goform/L7Prot. The manipulation of the argument page leads to stack-based… |
| CVE-2025-7548 | Alta (7.4) | 0.89% | — | 13 jul 2025 | A vulnerability has been found in Tenda FH1201 1.2.0.14(408) and classified as critical. This vulnerability affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument… |
| CVE-2025-7468 | Alta (7.4) | 0.89% | — | 12 jul 2025 | A vulnerability has been found in Tenda FH1201 1.2.0.14 and classified as critical. This vulnerability affects the function fromSafeUrlFilter of the file /goform/fromSafeUrlFilter of the component HTTP POST Request… |
| CVE-2025-7465 | Alta (7.4) | 0.89% | — | 12 jul 2025 | A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the function fromRouteStatic of the file /goform/fromRouteStatic of the component HTTP POST Request Handler.… |
| CVE-2025-7463 | Alta (7.4) | 1.1% | — | 12 jul 2025 | A vulnerability was found in Tenda FH1201 1.2.0.14. It has been declared as critical. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP POST Request… |
| CVE-2025-6110 | Alta (7.4) | 5.5% | — | 16 jun 2025 | A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page leads to stack-based buffer… |
| CVE-2024-12002 | Media (5.3) | 0.80% | — | 30 nov 2024 | A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of… |
| CVE-2024-44859 | Alta (8) | 0.62% | — | 4 sept 2024 | Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`. |
| CVE-2024-42955 | Alta (7.5) | 0.55% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2024-42952 | Alta (7.5) | 0.57% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST… |
| CVE-2024-42951 | Alta (7.5) | 0.55% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a… |
| CVE-2024-42950 | Alta (7.5) | 0.55% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2024-42948 | Alta (7.5) | 11% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2024-42947 | Crítica (9.8) | 0.98% | — | 15 ago 2024 | An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request. |
| CVE-2024-42946 | Alta (7.5) | 0.68% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST… |
| CVE-2024-42944 | Alta (7.5) | 0.68% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST… |
| CVE-2024-42943 | Alta (7.5) | 0.68% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2024-42941 | Alta (7.5) | 0.68% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST… |
| CVE-2024-42940 | Alta (7.5) | 0.68% | — | 15 ago 2024 | Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.