Tenda FH1202
cpe:2.3:h:tenda:fh1202:*:*:*:*:*:*:*, +3 more
- 1.2.0.14(408)
A critical vulnerability has been identified in the Tenda FH1202 router, specifically in version 1.2.0.14(408). This vulnerability resides within the web management interface, particularly in the '/goform/AdvSetWrl' file. It involves improper access controls, allowing unauthorized users to manipulate advanced settings of the device. The vulnerability can be exploited remotely without any authentication.
Exploitation of this vulnerability allows for unauthorized modification of the device's advanced settings, potentially leading to misconfiguration or other security issues.
To reproduce this vulnerability, send an unauthenticated HTTP POST request to the '/goform/AdvSetWrl' endpoint. The request must be crafted to exploit the improper access control, allowing the attacker to change advanced settings on the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.