CVE-2025-7465: Tenda FH1201 HTTP POST Request fromRouteStatic buffer overflow
Published Jul 12, 2025
·Updated
A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the function fromRouteStatic of the file /goform/fromRouteStatic of the component HTTP POST Request Handler. The manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda FH1201
All of the following
Tenda Fh1201 Firmware=1.2.0.14
Tenda FH1201
Event History
Jul 12, 2025
CVE Published
via MITRE·07:02 AM
Data Sourced
via MITRE·07:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 15, 57586
Event
via FIRST·03:21 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-7465?
CVE-2025-7465 is classified as a critical vulnerability.
2
How do I fix CVE-2025-7465?
To fix CVE-2025-7465, Tenda recommends updating to the latest firmware version that addresses this vulnerability.
3
What component is affected by CVE-2025-7465?
CVE-2025-7465 affects the HTTP POST Request Handler in the Tenda FH1201.
4
What type of vulnerability is CVE-2025-7465?
CVE-2025-7465 is a buffer overflow vulnerability.
5
In which file can CVE-2025-7465 be found?
CVE-2025-7465 is found in the file /goform/fromRouteStatic.