CVE-2025-14994: Tenda FH1201/FH1206 HTTP Request webtypelibrary strcat stack-based overflow
A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14994?
CVE-2025-14994 has a high severity due to its potential for causing stack-based buffer overflow vulnerabilities.
How do I fix CVE-2025-14994?
To fix CVE-2025-14994, update the firmware of Tenda FH1201 and FH1206 to the latest version provided by Tenda.
What products are affected by CVE-2025-14994?
CVE-2025-14994 affects the Tenda FH1201 and Tenda FH1206 routers.
What type of vulnerability is CVE-2025-14994?
CVE-2025-14994 is a stack-based buffer overflow vulnerability that can be exploited through HTTP requests.
Can CVE-2025-14994 be exploited remotely?
Yes, CVE-2025-14994 can be exploited remotely by manipulating HTTP requests sent to the affected devices.