CVE-2017-9139: Tendacn f1200 Firmware

Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.

There is a stack-based buffer overflow on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). Crafted POST requests to an unspecified URL result in DoS, interrupting the HTTP service (used to login to the web UI of a router) for 1 to 2 seconds.

Affected products

  • Tendacn f1200 Firmware: up to and including 1.2.0.19
  • Tendacn f1202 Firmware: up to and including 1.2.0.19
  • Tendacn FH1202 Firmware: up to and including 1.2.0.19

Published 2017-05-21. Last modified 2026-06-17.