CVE-2024-12002: Tenda FH1201 Firmware

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Content-Length leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Tenda FH1201 Firmware: version 1.2.0.8(8155) only; version 1.2.0.14(408)_en only
  • Tenda FH1202 Firmware: version 1.2.0.9 only; version 1.2.0.14(408) only; version 1.2.0.14(408)_en only
  • Tenda FH1206 Firmware: version 1.2.0.8(8155) only
  • Tenda FH451 Firmware: version 1.0.0.5 only; version 1.0.0.7 only; version 1.0.0.9 only

Published 2024-11-30. Last modified 2026-06-17.