CVE-2025-2996 is a critical improper access controls vulnerability affecting the Tenda FH1202 1.2.0.14(408) router, specifically within the web management interface's handling of the /goform/SysToolDDNS file. This remotely exploitable flaw has a CVSS score of 5.3 (Medium), indicating a low attack complexity and no user interaction required, potentially leading to unauthorized information disclosure or modification. While a public exploit has been disclosed, there are no known Metasploit or Nuclei modules, and it is not currently listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting low public awareness despite the disclosed exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.0.14\(408\)CPE matchmatch criteria | cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14\(408\):*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.