CVE-2026-3811
8.8Tenda · FH1202
A stack-based buffer overflow in the Tenda FH1202 web interface allows remote attackers to trigger denial of service or execute arbitrary code via the page parameter in /goform/P2pListFilter.
Executive summary
A critical stack-based buffer overflow vulnerability in the Tenda FH1202 router enables remote code execution and denial of service attacks.
Vulnerability
This vulnerability occurs within the fromP2pListFilter function of the /goform/P2pListFilter endpoint. An attacker can submit a maliciously crafted page parameter to trigger a stack-based buffer overflow due to a lack of bounds checking, which may lead to remote code execution.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve remote code execution, effectively granting them full control over the affected network device. This poses a severe risk of unauthorized internal network access, data interception, and complete device compromise. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent potential exploitation.
Remediation
Immediate Action: As no official patch is currently available, administrators should immediately restrict access to the device management interface to trusted internal segments only.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/P2pListFilter endpoint and review system logs for signs of unexpected device reboots or process crashes.
Compensating Controls: Deploy a Web Application Firewall or an intrusion detection system to filter or block HTTP requests containing abnormally large parameters directed at the /goform/P2pListFilter path.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the referenced researcher write-up.
Analyst recommendation
The presence of a public proof-of-concept significantly elevates the risk of exploitation by threat actors. Organizations utilizing the Tenda FH1202 router should prioritize isolating these devices from external access until the vendor releases a firmware update that addresses the buffer overflow. Continuous monitoring for anomalous traffic patterns is essential until a permanent fix is applied.
More Tenda CVEs
Sources
Originally found and disclosed by m202572177 (VulDB User), per the CVE Program record.
- VDB-349777 | Tenda FH1202 P2pListFilter fromP2pListFilter stack-based overflow Vulnerability database entry
- VDB-349777 | CTI Indicators (IOB, IOC, IOA)
- Submit #769041 | Tenda FH1202 V1.2.0.14(408) Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn