Tenda FH1202
cpe:2.3:h:tenda:fh1202:*:*:*:*:*:*:*, +3 more
- 1.2.0.14(408)
A critical vulnerability has been identified in the Tenda FH1202 router, specifically in version 1.2.0.14(408). The issue resides within the Web Management Interface, particularly in the file '/goform/AdvSetWrlsafeset'. This vulnerability allows for improper access controls, enabling unauthorized users to manipulate certain settings. The flaw can be exploited remotely without authentication.
Exploitation of this vulnerability allows for improper access control, where the device's safe settings can be altered by an unauthorized actor.
To reproduce this vulnerability, send an unauthenticated HTTP POST request to the '/goform/AdvSetWrlsafeset' endpoint. This request can be crafted to manipulate the safe settings of the Tenda FH1202 router.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.