Executive brief
A security vulnerability exists in the Tenda F1202 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the router or potentially take full control of the device by sending a specially crafted web request. This could lead to a complete loss of internet access or allow an unauthorized user to monitor network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the 'httpd' binary of the Tenda F1202 router, specifically within the 'fromPPTPUserSetting' function in the '/goform/PPTPUserSetting' file. The vulnerability is caused by the unsafe use of the 'sprintf' function when processing the user-provided 'delno' parameter without adequate length validation. A remote attacker with low privileges can exploit this by sending a crafted POST request, leading to memory corruption. This can result in a denial of service (DoS) or remote code execution (RCE). A public exploit (PoC) has been disclosed.
Affected products
- Tenda F1202 1.2.0.20(408)
Timeline
- 2026-05-25: disclosed: Vulnerability disclosed and CVE assigned via VulDB.
- 2026-05-25: advisory: NVD published the vulnerability record.