Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

Tenda Router: Remote Code Execution via Malicious Website ID

CVE-2026-3808
Summary

A flaw in the Tenda FH1202 router's web management interface allows an attacker to execute unauthorized code on the device by manipulating the website ID. This could allow an attacker to gain control of the router, potentially leading to data theft or disruption of the network. Users should update their router to the latest firmware to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
tenda fh1202_firmware 1.2.0.14\(408\) –
Original title
A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a manipulation of the argument web...
Original description
A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a manipulation of the argument webSiteId results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 7.4
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026