CVE-2025-14994
A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Vendor
Product
CWE
Yayın Tarihi
2025-12-21 08:15:49
Güncelleme
2025-12-31 15:40:06
Source Identifier
cna@vuldb.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_FH1201/webtyplibrary/webtypelibrary.md
https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_FH1206/webtyplibrary/webtypelibrary.md
https://vuldb.com/?ctiid.337688
https://vuldb.com/?id.337688
https://vuldb.com/?submit.719153
https://vuldb.com/?submit.719155
https://www.tenda.com.cn/