CVE-2025-14994
8.8Tenda · FH1201 and FH1206 Wireless Routers
A stack-based buffer overflow in Tenda FH1201 and FH1206 routers allows remote attackers to trigger memory corruption via the webSiteId parameter in the /goform/webtypelibrary endpoint.
Executive summary
A critical stack-based buffer overflow in Tenda FH1201 and FH1206 routers permits remote attackers to execute arbitrary code or cause a denial of service via malformed HTTP requests.
Vulnerability
This vulnerability is a stack-based buffer overflow occurring in the strcat function within the HTTP Request Handler. An authenticated user can trigger this memory corruption by sending a crafted HTTP GET request to the /goform/webtypelibrary endpoint with an excessively long webSiteId argument.
Business impact
The ability for a remote attacker to achieve arbitrary code execution on networking infrastructure poses a severe risk to organizational security. Successful exploitation could lead to full device compromise, unauthorized network traffic interception, or persistent denial of service, severely impacting business operations. With a CVSS score of 8.8, this vulnerability is classified as High and demands immediate attention to prevent lateral movement within the local network.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should immediately restrict access to the web management interface of affected Tenda routers to trusted management IP addresses only.
Proactive Monitoring: Review device logs for unusual HTTP GET requests targeting the /goform/webtypelibrary URI, specifically monitoring for anomalous lengths in the webSiteId parameter.
Compensating Controls: If management interface access cannot be restricted, ensure that the router is not exposed to the public internet and utilize network segmentation to isolate administrative traffic from user-facing segments.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists in the researcher's technical write-up on GitHub.
Analyst recommendation
Given the availability of public proof-of-concept code and the critical nature of buffer overflow vulnerabilities in network hardware, the risk is significant. Organizations using these Tenda devices must treat this as a priority, ensuring that administrative interfaces are not exposed to untrusted networks while awaiting official vendor firmware updates.
More Tenda CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written
Sources
Originally found and disclosed by z472421519 (VulDB User), per the CVE Program record.
- VDB-337688 | Tenda FH1201/FH1206 HTTP Request webtypelibrary strcat stack-based overflow Vulnerability database entry
- VDB-337688 | CTI Indicators (IOB, IOC, IOA)
- Submit #719153 | Tenda FH1201 V1.2.0.14(408) Stack-based Buffer Overflow Third-party advisory
- Submit #719155 | Tenda FH1206 1.2.0.8(8155) Stack-based Buffer Overflow (Duplicate) Third-party advisory
- Exploit / PoC
- Exploit / PoC
- tenda.com.cn