CVE-2025-7528: Tenda FH1202 GstDhcpSetSer fromGstDhcpSetSer stack-based overflow
Published Jul 13, 2025
·Updated
A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argument dips leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda FH1202
All of the following
Tenda Fh1202 Firmware=1.2.0.14\(408\)
Tenda FH1202
Event History
Jul 13, 2025
CVE Published
via MITRE·11:32 AM
Data Sourced
via MITRE·11:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 10, 57589
Event
via FIRST·07:17 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7528?
CVE-2025-7528 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-7528?
CVE-2025-7528 is a stack-based buffer overflow vulnerability.
3
Which devices are affected by CVE-2025-7528?
CVE-2025-7528 affects the Tenda FH1202 version 1.2.0.14(408).
4
How can CVE-2025-7528 be exploited?
CVE-2025-7528 can be exploited remotely by manipulating the argument 'dips' in the function fromGstDhcpSetSer.
5
How do I mitigate CVE-2025-7528?
To mitigate CVE-2025-7528, update the firmware of the Tenda FH1202 to the latest version provided by the vendor.