Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26370 | A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. |
Wed, 31 Dec 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda f1202 Firmware
|
|
| CPEs | cpe:2.3:o:tenda:fh1202_firmware:1.2.0.20:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:* |
cpe:2.3:o:tenda:f1202_firmware:1.2.0.14:*:*:*:*:*:*:* cpe:2.3:o:tenda:f1202_firmware:1.2.0.20:*:*:*:*:*:*:* cpe:2.3:o:tenda:f1202_firmware:1.2.0.9:*:*:*:*:*:*:* |
| Vendors & Products |
Tenda fh1202 Firmware
|
Tenda f1202 Firmware
|
Tue, 21 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda fh1202 Firmware
|
|
| CPEs | cpe:2.3:h:tenda:f1202:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1202_firmware:1.2.0.14:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1202_firmware:1.2.0.20:*:*:*:*:*:*:* cpe:2.3:o:tenda:fh1202_firmware:1.2.0.9:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda fh1202 Firmware
|
Tue, 02 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda f1202 |
|
| Vendors & Products |
Tenda
Tenda f1202 |
Tue, 02 Sep 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. | |
| Title | Tenda F1202 Administrative shadow hard-coded credentials | |
| Weaknesses | CWE-259 CWE-798 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-02T19:33:32.924Z
Reserved: 2025-09-01T15:09:53.760Z
Link: CVE-2025-9806
Updated: 2025-09-02T19:32:37.462Z
Status : Analyzed
Published: 2025-09-02T01:15:30.957
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9806
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:07Z
EUVD