VendorsTendafh1206any version
Vulnerabilities

Tenda FH1206 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2024-35339
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
Published 2024-05-24 · Analyzed
9.8EPSS 0.018
CVE-2024-7615
Tenda FH1206 fromSafeUrlFilter stack-based overflow
Published 2024-08-08 · Analyzed
9.8EPSS 0.015
CVE-2024-7613
Tenda FH1206 GstDhcpSetSer fromGstDhcpSetSer buffer overflow
Published 2024-08-08 · Analyzed
9.8EPSS 0.015
CVE-2024-7614
Tenda FH1206 qossetting fromqossetting stack-based overflow
Published 2024-08-08 · Analyzed
9.8EPSS 0.015
CVE-2024-7707
Tenda FH1206 HTTP POST Request SafeEmailFilter formSafeEmailFilter stack-based overflow
Published 2024-08-13 · Analyzed
9.8EPSS 0.013
CVE-2024-42978
An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.
Published 2024-08-15 · Modified
9.8EPSS 0.012
CVE-2024-34943
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.
Published 2024-05-10 · Analyzed
9.8EPSS 0.009
CVE-2024-34945
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.
Published 2024-05-10 · Analyzed
9.8EPSS 0.009
CVE-2024-33215
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.
Published 2024-04-23 · Analyzed
9.8EPSS 0.007
CVE-2024-4020
Tenda FH1206 addressNat fromAddressNat buffer overflow
Published 2024-04-20 · Analyzed
9.0EPSS 0.016
CVE-2025-14994
Tenda FH1201/FH1206 HTTP Request webtypelibrary strcat stack-based overflow
Published 2025-12-21 · Analyzed
9.0EPSS 0.007
CVE-2024-34942
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.
Published 2024-05-10 · Analyzed
8.8EPSS 0.009
CVE-2024-33212
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in ip/goform/setcfm.
Published 2024-04-23 · Analyzed
8.8EPSS 0.007
CVE-2024-34944
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.
Published 2024-05-10 · Analyzed
8.8EPSS 0.004
CVE-2024-44390
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.
Published 2024-08-23 · Analyzed
8.8EPSS 0.003
CVE-2024-35340
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.
Published 2024-05-24 · Analyzed
8.6EPSS 0.012
CVE-2024-42987
Tenda FH1206 v02.03.01.35 was discovered to contain a stack-based buffer overflow vulnerability in the fromPptpUserAdd function. The vulnerability can be triggered via the modino, username, newpwd, or pptpdnetseg parameters, all of which are passed via HTTP POST and used in unsafe sprintf calls without proper length validation. A remote attacker can exploit this flaw through a crafted POST request, which may cause a Denial of Service (DoS). In certain scenarios, this issue could potentially be leveraged to achieve remote code execution.
Published 2024-08-15 · Modified
7.5EPSS 0.013
CVE-2024-33217
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.
Published 2024-04-23 · Analyzed
7.5EPSS 0.006
CVE-2024-33214
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter in ip/goform/RouteStatic.
Published 2024-04-23 · Analyzed
7.5EPSS 0.006
CVE-2024-42973
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Analyzed
7.5EPSS 0.006
CVE-2024-42969
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42968
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Analyzed
7.5EPSS 0.006
CVE-2024-42977
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42986
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42985
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42984
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Analyzed
7.5EPSS 0.006
CVE-2024-42983
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Analyzed
7.5EPSS 0.006
CVE-2024-42982
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42981
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42980
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42979
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Analyzed
7.5EPSS 0.006
CVE-2024-42976
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Modified
7.5EPSS 0.006
CVE-2024-42974
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Published 2024-08-15 · Analyzed
7.5EPSS 0.006
CVE-2024-33211
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in ip/goform/QuickIndex.
Published 2024-04-23 · Analyzed
7.3EPSS 0.004
CVE-2024-44386
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.
Published 2024-08-23 · Analyzed
7.3EPSS 0.003
CVE-2024-12002
Tenda FH451/FH1201/FH1202/FH1206 GetIPTV websReadEvent null pointer dereference
Published 2024-11-30 · Analyzed
6.5EPSS 0.008
CVE-2024-34946
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.
Published 2024-05-10 · Analyzed
6.5EPSS 0.007
CVE-2024-33213
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic.
Published 2024-04-23 · Analyzed
6.5EPSS 0.004
CVE-2024-44387
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.
Published 2024-08-23 · Analyzed
6.5EPSS 0.003