← back
CVE-2025-2992

Tenda FH1202 Web Management Interface AdvSetWrlsafeset access control

CVSS 6.9 MEDIUMEPSS 0.6%CWE-266CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
31 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability classified as critical was found in Tenda FH1202 1.2.0.14(408). Affected by this vulnerability is an unknown functionality of the file /goform/AdvSetWrlsafeset of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Tenda · FH1202

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →