Executive brief
A security vulnerability exists in the Tenda F1202 wireless router, a device used to provide home and small office internet connectivity. An attacker can exploit this flaw to crash the router or potentially take full control of the device. This could lead to a complete loss of internet access or the interception of network traffic.
Technical details
A stack-based buffer overflow vulnerability (CWE-121) exists in the Tenda F1202 router firmware version 1.2.0.20(408). The flaw is located within the 'formGstDhcpSetSer' function in the '/goform/GstDhcpSetSer' component (noted as GstDhcpSetSerof in some reports). The vulnerability is triggered by insufficient length validation of the 'dips' argument, which is processed via unsafe string operations. A remote attacker with low privileges can exploit this by sending a specially crafted HTTP request to the device's web interface. Successful exploitation can lead to a denial of service (DoS) or remote code execution (RCE). Public exploit details have been disclosed.
Affected products
- Tenda F1202 1.2.0.20(408)
Timeline
- 2026-05-25: advisory: NVD publication date
- 2026-05-25: disclosed: Public disclosure of the vulnerability and PoC