CVE-2026-3808Disclosure(tenda / fh1202)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for tenda fh1202 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a manipulation of the argument webSiteId results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fh1202
  • fh1202_firmware

Threat summary

  • Exploit tooling references are present in monitored signal
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-09); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
fh1202fh1202_firmware

2 versions affected across 2 products

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-09: 3Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Exploit Tool / Code · 2026-03-09: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-0903-1003-1203-13
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-093
Disclosure2General1
2026-03-102
Disclosure1General1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3808 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of t..https://nvd.nist.gov/vuln/detail/CVE-2026-3808 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post reports the discovery and analysis of CVE‑2026‑3808 in a Tenda FH1202 router, giving a high CVSS score and specific affected function, but offers no evidence of exploitation, mitigations, or PoC details.

    0000054
    172 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3808 (CVSS:7.4, HIGH) is Analyzed. A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of t..https://nvd.nist.gov/vuln/detail/CVE-2026-3808 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-3808, giving its CVSS score, severity, and the affected component, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000032
    172 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3808 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3808 #CVE-2026-3808 #CVE #High  #CyberSecurity #InfoSec https://t.co/alvsoh2gjM

    Post summary

    The tweet announces the discovery of CVE‑2026‑3808, noting its CVSS score of 8.8 and high risk level, while linking to the NVD entry for further details.

    0000025
    92 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-3808 - Tenda - FH1202 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3808-tenda-fh1202/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3808 #tenda #fh1202

    Post summary

    The post merely announces CVE‑2026‑3808 and provides a link, offering no additional technical or operational details.

    0000071
    3.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3808 A vulnerability was detected in Tenda FH1202 1.2.0.14(408). The affected element is the function formWebTypeLibrary of the file /goform/webtypelibrary. Performing a man… https://www.cve.org/CVERecord?id=CVE-2026-3808

    Post summary

    The text briefly references CVE-2026-3808, noting the affected function but provides no actionable information such as a PoC, exploit, or mitigation.

    00000120
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3808 Stack-Based Buffer Overflow in Tenda FH1202 Router via WebSiteId Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3808

    Post summary

    The post announces a newly disclosed stack‑based buffer overflow vulnerability in Tenda FH1202 routers, directing readers to a vulnerability details page.

    0000037
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3808: HIGH] Critical vulnerability in Tenda FH1202 1.2.0.14(408)! Exploit allows remote attackers to trigger a stack-based buffer overflow via manipulated webSiteId argument. Protect your systems now.#cve,CVE-2026-3808,#cybersecurity https://cvefind.com/CVE-2026-3808

    Post summary

    The post announces a high‑severity CVE-2026-3808 affecting Tenda FH1202, detailing a stack-based buffer overflow exploitable via a manipulated webSiteId parameter; no patch, PoC, or active exploitation is reported.

    0000047
    600 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendafh1202---
OStendafh1202_firmware1.2.0.14\(408\)--

Explore more