CVE Tools

CVE-2025-2993

Tenda FH1202 default.cfg access control

Published: Mar 31, 2025Updated: Apr 8, 2025 Sources: CVE List NVD BDUCWE-266

Description

A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file /default.cfg. The manipulation of the argument these leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

In plain language

AI Worth attention

A flaw in Tenda FH1202 default configuration (often reachable as /default.cfg) lets an attacker on the network view sensitive settings without logging in; a typical small business should check whether their router is exposed to the internet and fix the firmware ASAP.

Executive summary

In Tenda FH1202 firmware, an access-control weakness in the remotely reachable /default.cfg allows unauthorized disclosure of sensitive configuration information without authentication, and a public exploit is available.

If affected, business impact
Sensitive settings exposureAccount/credential exposure riskDevice/network takeover facilitationPrivacy and configuration leakage

What to do now

  1. Check whether your Tenda FH1202 is reachable from the internet (for example, whether you have port-forwarding enabled for web management or other external access).
  2. Confirm your current firmware version on the router (your admin page) and see if it matches the affected line described for Tenda FH1202 (including 1.2.0.14(408)).
  3. If your firmware is affected, update to the vendor’s fixed firmware version as soon as it’s available.
  4. Restrict external access using your firewall (block inbound access to the router from the internet, and remove any unnecessary port forwards).
Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:LI:NA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:LConfidentiality
Low
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 4 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-2993 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store