CVE-2025-3236: Tenda FH1202 Web Management Interface VirSerDMZ access control
Published Apr 4, 2025
·Updated
A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/VirSerDMZ of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda FH1202
All of the following
Tenda Fh1202 Firmware=1.2.0.14\(408\)
Tenda FH1202
Event History
Apr 4, 2025
CVE Published
via MITRE·09:31 AM
Data Sourced
via MITRE·09:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Jul 11, 57244
Event
via FIRST·09:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-3236?
CVE-2025-3236 has been declared as critical.
2
What component is affected by CVE-2025-3236?
CVE-2025-3236 affects the Web Management Interface of the Tenda FH1202.
3
How does CVE-2025-3236 impact system security?
CVE-2025-3236 leads to improper access controls, which can allow unauthorized manipulation.
4
What software version is impacted by CVE-2025-3236?
CVE-2025-3236 affects Tenda FH1202 version 1.2.0.14(408).
5
How do I fix CVE-2025-3236?
To fix CVE-2025-3236, apply the latest firmware update provided by Tenda for the FH1202.