Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9806

Опубликовано: 02 сент. 2025
Источник: nvd
CVSS3: 1.9
CVSS3: 6.4
CVSS2: 0.8
EPSS Низкий

Описание

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14:*:*:*:*:*:*:*
cpe:2.3:o:tenda:fh1202_firmware:1.2.0.20:*:*:*:*:*:*:*
cpe:2.3:h:tenda:f1202:-:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00014
Низкий

1.9 Low

CVSS3

6.4 Medium

CVSS3

0.8 Low

CVSS2

Дефекты

CWE-259

Связанные уязвимости

CVSS3: 6.4
github
около 1 месяца назад

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.

CVSS3: 1.9
fstec
3 месяца назад

Уязвимость административного интерфейса микропрограммного обеспечения маршрутизаторов Tenda F1202, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 2%
0.00014
Низкий

1.9 Low

CVSS3

6.4 Medium

CVSS3

0.8 Low

CVSS2

Дефекты

CWE-259