CVE-2025-2995: Tenda FH1202 Web Management Interface SysToolChangePwd access control
Published Mar 31, 2025
·Updated
A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. This vulnerability affects unknown code of the file /goform/SysToolChangePwd of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda FH1202
All of the following
Tenda Fh1202 Firmware=1.2.0.14\(408\)
Tenda FH1202
Event History
Mar 31, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-2995?
CVE-2025-2995 is classified as a critical vulnerability.
2
How do I fix CVE-2025-2995?
To fix CVE-2025-2995, update the Tenda FH1202 firmware to the latest version provided by the vendor.
3
What component is affected by CVE-2025-2995?
CVE-2025-2995 affects the Web Management Interface of the Tenda FH1202 device.
4
What type of vulnerability is CVE-2025-2995?
CVE-2025-2995 is related to improper access controls.
5
Which product is impacted by CVE-2025-2995?
CVE-2025-2995 impacts the Tenda FH1202 router.