Impact
Tenda FH1202 routers running firmware 1.2.0.14(408) contain a stack‑based buffer overflow in the fromP2pListFilter function of the /goform/P2pListFilter page. Manipulating the page argument can overflow the stack, allowing an attacker to execute arbitrary code on the device. The attack can be performed remotely and the exploit has been made publicly available, indicating a legitimate threat channel.
Affected Systems
The affected device is the Tenda FH1202 home router. The vulnerable firmware version is 1.2.0.14(408). No other Tenda products or firmware revisions are listed as affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of less than 1% suggests that, despite high impact, the likelihood of real‑world exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog at this time. Nevertheless, because the flaw permits remote exploitation via a known HTTP endpoint, any exposed infrastructure could be compromised if an attacker gains access to the router’s management interface.
OpenCVE Enrichment