CVE-2025-69700

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to execute arbitrary code on the Tenda FH1203 router by exploiting a flaw in a specific function that handles client priority settings. To take advantage of this, the attacker must have access to the router's web interface, which typically requires being on the same network.

Technical Description

Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactNone
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$2,053($1K-$5K)
Vendor Response
Grade APatched in 1 day

Quick Information

Published

Feb 23, 2026

about 1 month ago

Last Modified

Feb 24, 2026

about 1 month ago

Vendor

tenda

Product

fh1203 firmware

Related Vulnerabilities

CVE-2026-3811High

An attacker can remotely exploit a vulnerability in Tenda FH1202 routers to execute arbitrary code by sending specially crafted data to a specific function, which can lead to a crash or unauthorized control of the device. This attack requires no physical access and can be carried out over the internet, making it a significant risk for users with this firmware version.

CVE-2026-3810High

This vulnerability allows an attacker to remotely take control of the Tenda FH1202 router by exploiting a flaw in its DHCP client list function, which can lead to a crash or unauthorized access to the device. The attacker needs to send specially crafted data to the router, making it possible for them to execute harmful code on the device.

CVE-2026-3809High

An attacker can remotely exploit a flaw in the Tenda FH1202 router's firmware to execute arbitrary code by manipulating a specific setting, potentially taking control of the device. This vulnerability requires no special access, making it easy for attackers to target affected routers over the internet.

CVE-2026-3808High

This vulnerability allows an attacker to remotely execute malicious code on the Tenda FH1202 router by exploiting a flaw in how the device handles certain input data. The attacker needs to manipulate a specific argument in the router's web interface, which could lead to unauthorized access or control of the device.

CVE-2026-3807High

An attacker can remotely exploit a vulnerability in the Tenda FH1202 router to execute arbitrary code by sending specially crafted data that causes a buffer overflow, potentially taking control of the device. This attack can happen without needing physical access, making it a serious risk for users of this router firmware version.