Improper Access Controls in Tenda FH1202 Web Management Interface
CVE-2025-3236
Key Information:
Badges
Summary
A vulnerability in the Tenda FH1202's Web Management Interface has been identified, which allows for improper access controls through the manipulation of the /goform/VirSerDMZ file. This flaw can be exploited remotely, enabling unauthorized access to sensitive functions of the device. Rapid disclosure of this exploit raises concerns regarding its potential use in attacks against systems using this product, necessitating immediate awareness and action for affected users.
Affected Version(s)
FH1202 1.2.0.14(408)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved