Description
A vulnerability has been found in Tenda FH1202 1.2.0.14(408). This affects the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Published: 2026-03-09
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack-based buffer overflow exists in the fromDhcpListClient function of the /goform/DhcpListClient page on Tenda FH1202 routers. The flaw is triggered by sending a specially crafted value for the page argument, which overflows a local stack buffer and can corrupt control data. Because the overflow can overwrite return addresses, the vulnerability can lead to arbitrary code execution on the device. The attack compromises confidentiality, integrity, and availability, as a successful exploit would give an attacker full control of the router.

Affected Systems

The affected device is the Tenda FH1202 router running firmware version 1.2.0.14(408). No other firmware versions are listed as vulnerable; newer releases may contain the fix or mitigation.

Risk and Exploitability

The CVSS base score is 8.7, indicating high severity. The EPSS score is below 1 %, suggesting a low current exploitation probability, although the flaw is publicly disclosed. The vulnerability is not included in CISA’s KEV catalog. The /goform/DhcpListClient endpoint is reachable over the local network, and the attack is considered network-based. This inference comes from the fact that the exploit is delivered via HTTP requests to that endpoint, implying that the attacker needs network access to the router. Consequently, devices exposed to the internet or untrusted networks remain at significant risk.

Generated by OpenCVE AI on April 18, 2026 at 09:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the FH1202 router to the latest firmware released by Tenda, which includes a fixed handler for the /goform/DhcpListClient page.
  • If a firmware update is not yet available, block or restrict external access to the /goform/DhcpListClient endpoint by configuring firewall rules or placing the device on a separate VLAN.
  • Disable the DHCP client feature if it is not required and isolate the router from untrusted networks to limit the attack surface.

Generated by OpenCVE AI on April 18, 2026 at 09:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda fh1202
CPEs cpe:2.3:h:tenda:fh1202:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:*
Vendors & Products Tenda fh1202

Mon, 09 Mar 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Tenda FH1202 1.2.0.14(408). This affects the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Title Tenda FH1202 DhcpListClient fromDhcpListClient stack-based overflow
First Time appeared Tenda
Tenda fh1202 Firmware
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:o:tenda:fh1202_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda fh1202 Firmware
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Tenda Fh1202 Fh1202 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-10T16:05:06.793Z

Reserved: 2026-03-08T16:22:52.352Z

Link: CVE-2026-3810

cve-icon Vulnrichment

Updated: 2026-03-10T16:05:03.839Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-09T08:16:01.480

Modified: 2026-03-09T15:26:46.373

Link: CVE-2026-3810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T09:45:25Z

Weaknesses