Executive brief
A vulnerability exists in the Tenda F1202 wireless router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to crash the router or potentially take full control of the device. This could lead to a complete loss of internet access or allow an unauthorized person to monitor network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the 'httpd' binary of the Tenda F1202 router (version 1.2.0.20(408)). The issue resides in the 'fromPptpUserAdd' function within the '/goform/PptpUserAdd' (or '/goform/PPTPDClient') endpoint. When the 'opttype' parameter is set to 1, the 'username' parameter is processed by an 'sprintf' function call without adequate length validation, leading to a buffer overflow on the stack. A remote attacker with low privileges (authenticated) can exploit this by sending a specially crafted POST request containing an excessively long string. Successful exploitation can result in a denial of service (DoS) or remote code execution (RCE). A public exploit (PoC) is available.
Affected products
- Tenda F1202 1.2.0.20(408)
Timeline
- 2026-05-25: disclosed: Vulnerability reported via VulDB and NVD