CVE-2025-69700
7.5Tenda · FH1203 V2
The Tenda FH1203 V2 router contains a stack-based buffer overflow in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.
Executive summary
A stack-based buffer overflow in the Tenda FH1203 V2 router allows unauthenticated attackers to trigger a denial of service condition.
Vulnerability
This vulnerability is a stack-based buffer overflow located in the modify_add_client_prio function. It is reachable via the formSetClientPrio CGI handler and can be triggered by unauthenticated remote attackers.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk primarily due to its potential for service disruption. Successful exploitation allows an attacker to cause a denial of service, rendering the affected network infrastructure unresponsive and potentially forcing a device reboot or complete system hang. This could lead to significant operational downtime for users relying on the device for network connectivity.
Remediation
Immediate Action: Since a vendor patch is currently unknown, administrators should isolate the management interface of the Tenda FH1203 V2 device from the public internet to prevent unauthorized access.
Proactive Monitoring: Review device access logs for unusual traffic directed at the formSetClientPrio CGI handler or unexpected device reboots.
Compensating Controls: Implement access control lists on the network perimeter to restrict traffic to the router management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the existence of a proof-of-concept, this vulnerability poses a credible risk to network availability. Administrators must prioritize restricting access to the management interface immediately, as no official vendor patch is currently confirmed. Continued vigilance and monitoring for signs of exploitation are essential until a permanent firmware update is released by the manufacturer.