Vulnerabilities (CVE)

Filtered by vendor Tenda Subscribe
Filtered by product Fh1206 Firmware
Total 37 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-35340 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-09 N/A 8.6 HIGH
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.
CVE-2024-35339 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-09 N/A 9.8 CRITICAL
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
CVE-2024-34942 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 8.8 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.
CVE-2024-34943 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 9.8 CRITICAL
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.
CVE-2024-34944 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 8.8 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.
CVE-2024-44386 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 7.3 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.
CVE-2024-34945 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 9.8 CRITICAL
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.
CVE-2024-34946 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 N/A 6.5 MEDIUM
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.
CVE-2024-42978 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-25 N/A 9.8 CRITICAL
An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2024-33215 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-17 N/A 9.8 CRITICAL
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.
CVE-2024-33214 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-17 N/A 7.5 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter in ip/goform/RouteStatic.
CVE-2024-33212 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-17 N/A 8.8 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in ip/goform/setcfm.
CVE-2024-33211 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-17 N/A 7.3 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in ip/goform/QuickIndex.
CVE-2024-33213 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-17 N/A 6.5 MEDIUM
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic.
CVE-2024-33217 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-03-17 N/A 7.5 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.
CVE-2024-44387 1 Tenda 2 Fh1206, Fh1206 Firmware 2024-12-13 N/A 6.5 MEDIUM
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet.
CVE-2024-44390 1 Tenda 2 Fh1206, Fh1206 Firmware 2024-12-13 N/A 8.8 HIGH
Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.
CVE-2024-12002 1 Tenda 8 Fh1201, Fh1201 Firmware, Fh1202 and 5 more 2024-12-10 4.0 MEDIUM 4.3 MEDIUM
A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-42986 1 Tenda 2 Fh1206, Fh1206 Firmware 2024-10-24 N/A 7.5 HIGH
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-42977 1 Tenda 2 Fh1206, Fh1206 Firmware 2024-10-24 N/A 7.5 HIGH
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.