CVE-2025-6110

Tenda · FH1201

A critical vulnerability has been identified in the Tenda FH1201 router, potentially allowing unauthorized system impact.

Executive summary

A critical security vulnerability in the Tenda FH1201 router poses a severe risk of unauthorized system compromise and potential device takeover.

Vulnerability

The vulnerability is classified as critical, though specific technical parameters remain under investigation; it likely involves insufficient input validation or authentication handling.

Business impact

With a CVSS score of 8.8, this vulnerability represents a high-severity risk. Successful exploitation could lead to full device compromise, enabling attackers to intercept network traffic, modify configuration settings, or pivot into internal network segments, resulting in significant operational downtime and data exposure.

Remediation

Immediate Action: Check the Tenda support portal for firmware updates and apply them immediately to all affected hardware.

Proactive Monitoring: Monitor network traffic for anomalous outbound connections and review device access logs for unauthorized administrative login attempts.

Compensating Controls: Restrict management interface access to trusted internal IP addresses and disable remote administration features until a patch is applied.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score, immediate attention is required to secure these devices. Administrators should prioritize firmware updates and isolate affected routers from public-facing exposure until remediation is confirmed.