CVE-2025-9806EPSS p4.2%
CVE-2025-9806CVE-2025-9806
tenda / f1202_firmware
Description
A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.
Scoring
| CVSS | 1.9 () |
| Vector | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.16% probability of exploitation · percentile 4.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |