CVE-2026-3808: Tenda FH1202 webtypelibrary formWebTypeLibrary stack-based overflow
A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a manipulation of the argument webSiteId results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3808?
CVE-2026-3808 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-3808?
To fix CVE-2026-3808, update the Tenda FH1202 device firmware to the latest version provided by the vendor.
What is the impact of CVE-2026-3808?
The impact of CVE-2026-3808 includes the possibility of remote attackers gaining unauthorized access and executing arbitrary code on the affected device.
Which products are affected by CVE-2026-3808?
CVE-2026-3808 affects the Tenda FH1202 firmware version 1.2.0.14(408).
How is CVE-2026-3808 exploited?
CVE-2026-3808 can be exploited by manipulating the argument 'webSiteId' in the formWebTypeLibrary function, resulting in a stack-based buffer overflow.