CVE-2024-42947: Tenda FH1201 Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.

Affected products

  • Tenda FH1201 Firmware: version 1.2.0.14(408) only

Published 2024-08-15. Last modified 2026-06-17.