


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in Tenda FH1202 1.2.0.14(408). The impacted element is the function fromNatStaticSetting of the file /goform/NatSaticSetting. Executing a …
Published:
8 maart 2026 om 23:00:00
Alert date:
9 maart 2026 om 16:03:25
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A critical stack-based buffer overflow vulnerability has been discovered in Tenda FH1202 router firmware version 1.2.0.14(408). The flaw exists in the fromNatStaticSetting function within the /goform/NatSaticSetting file. Attackers can exploit this vulnerability by manipulating the 'page' argument parameter. The vulnerability can be exploited remotely, making it particularly dangerous for internet-connected devices. Public exploit code has been published and is available for use, increasing the immediate threat level. This affects the router's NAT static setting functionality and could potentially allow attackers to execute arbitrary code or cause denial of service.
Technical details
Mitigation steps:
Affected products:
Tenda FH1202
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3809
https://github.com/Svigo-o/Tenda_vul/tree/main/tenda-fh1202-natsaticsetting-page-buffer-overflow
https://vuldb.com/?ctiid.349775
https://vuldb.com/?id.349775
https://vuldb.com/?submit.769039
https://www.tenda.com.cn/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
