CVE-2025-2994: Tenda FH1202 Web Management Interface qossetting access control
A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2994?
CVE-2025-2994 is classified as a critical vulnerability.
How do I fix CVE-2025-2994?
To fix CVE-2025-2994, update the Tenda FH1202 firmware to the latest version provided by the manufacturer.
What component is affected by CVE-2025-2994?
CVE-2025-2994 affects the Web Management Interface component of the Tenda FH1202 router.
What kind of vulnerability is CVE-2025-2994?
CVE-2025-2994 is an access control vulnerability that allows improper manipulation.
What potential impact does CVE-2025-2994 have on my device?
Exploitation of CVE-2025-2994 could lead to unauthorized access to sensitive settings on the Tenda FH1202.