Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-9806


A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.


Published

2025-09-02T01:15:30.957

Last Modified

2025-12-31T00:48:39.297

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 1.9 (LOW)

CVSSv2 Vector

AV:L/AC:H/Au:M/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: HIGH
  • Authentication: MULTIPLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

1.2

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-259
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tenda f1202_firmware 1.2.0.9 Yes
Operating System tenda f1202_firmware 1.2.0.14 Yes
Operating System tenda f1202_firmware 1.2.0.20 Yes
Hardware tenda f1202 - No

References