CVE-2025-2991: Tenda FH1202 Web Management Interface AdvSetWrlmacfilter access control
Published Mar 31, 2025
·Updated
A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmacfilter of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda FH1202
All of the following
Tenda Fh1202 Firmware=1.2.0.14\(408\)
Tenda FH1202
Event History
Mar 31, 2025
CVE Published
via MITRE·10:31 AM
Data Sourced
via MITRE·10:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
May 11, 57220
Event
via FIRST·02:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-2991?
CVE-2025-2991 is classified as a critical severity vulnerability.
2
How do I fix CVE-2025-2991?
To fix CVE-2025-2991, update the Tenda FH1202 firmware to the latest version available.
3
What component is affected by CVE-2025-2991?
CVE-2025-2991 affects the Web Management Interface of the Tenda FH1202.
4
What type of vulnerability is CVE-2025-2991?
CVE-2025-2991 is an improper access control vulnerability.
5
Can CVE-2025-2991 be exploited remotely?
Yes, CVE-2025-2991 can potentially be exploited remotely due to its nature.