---
id: CVE-2025-9806
title: A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20
summary: >-
  A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20.
  Impacted is an unknown function of the file /etc_ro/shadow of the component
  Administrative Interface. This manipulation with the input Fireitup causes
  hard-coded cr…
severity: low
cvss: 1.9
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-259
  - CWE-798
vendor: tenda
product: f1202_firmware
affected:
  - f1202_firmware = 1.2.0.9
  - f1202_firmware = 1.2.0.14
  - f1202_firmware = 1.2.0.20
published: '2025-09-02'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9806'
references:
  - url: 'https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e9.md'
    label: cna@vuldb.com
  - url: >-
      https://github.com/August829/Yu/blob/main/58ead8e7e08bfb0e9.md#steps-to-reproduce
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.322130'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.322130'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.640980'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00157
epssPercentile: 0.04186
ingestedAt: '2026-09-30T23:29:32.352Z'
---

## Overview

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.

## Affected

- `f1202_firmware = 1.2.0.9`
- `f1202_firmware = 1.2.0.14`
- `f1202_firmware = 1.2.0.20`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
