📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Financial Services, Banking HIGH 3h Global vulnerability Technology and Software Development HIGH 5h Global vulnerability Government and Federal Agencies CRITICAL 6h Global supply_chain Software Development and Open-Source Ecosystems HIGH 6h Global vulnerability Enterprise Software/SaaS MEDIUM 7h Global supply_chain Software Development HIGH 7h Global general Insurance/Risk Management HIGH 7h Global data_breach Enterprise Software / Information Technology CRITICAL 8h Global vulnerability Technology/Software CRITICAL 10h Global malware Social Media and Consumer Technology HIGH 10h Global apt Financial Services, Banking HIGH 3h Global vulnerability Technology and Software Development HIGH 5h Global vulnerability Government and Federal Agencies CRITICAL 6h Global supply_chain Software Development and Open-Source Ecosystems HIGH 6h Global vulnerability Enterprise Software/SaaS MEDIUM 7h Global supply_chain Software Development HIGH 7h Global general Insurance/Risk Management HIGH 7h Global data_breach Enterprise Software / Information Technology CRITICAL 8h Global vulnerability Technology/Software CRITICAL 10h Global malware Social Media and Consumer Technology HIGH 10h Global apt Financial Services, Banking HIGH 3h Global vulnerability Technology and Software Development HIGH 5h Global vulnerability Government and Federal Agencies CRITICAL 6h Global supply_chain Software Development and Open-Source Ecosystems HIGH 6h Global vulnerability Enterprise Software/SaaS MEDIUM 7h Global supply_chain Software Development HIGH 7h Global general Insurance/Risk Management HIGH 7h Global data_breach Enterprise Software / Information Technology CRITICAL 8h Global vulnerability Technology/Software CRITICAL 10h Global malware Social Media and Consumer Technology HIGH 10h
Vulnerabilities

CVE-2026-9430

High
CWE-119 — Weakness Type
Published: May 25, 2026  ·  Modified: Jun 1, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this issue is the function formGstDhcpSetSer of the file /goform/GstDhcpSetSerof. Executing a manipulation of the argument dips can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

🤖 AI Executive Summary

A stack-based buffer overflow vulnerability exists in Tenda F1202 router firmware version 1.2.0.20(408) affecting the DHCP configuration function. The vulnerability allows remote attackers to execute arbitrary code by manipulating the 'dips' parameter, with a CVSS score of 8.8. No patch is currently available, making this a critical threat to organizations using this router model.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 28, 2026 19:04
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi telecommunications infrastructure (STC, Mobily, Zain), government agencies, and banking institutions that may use Tenda F1202 routers in branch offices or remote locations. The vulnerability is particularly critical for ARAMCO and energy sector facilities relying on these routers for network connectivity. Financial institutions regulated by SAMA face compliance violations if exploited. The remote nature of the attack and lack of authentication requirements make this especially dangerous for critical infrastructure protected under NCA oversight.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Banking and Financial Services (SAMA regulated) Energy and Oil & Gas (ARAMCO, downstream) Government and Public Administration (NCA oversight) Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
8.9
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Tenda F1202 routers running firmware 1.2.0.20(408) in your network using network scanning tools
2. Isolate affected routers from critical systems and segment network access
3. Implement network-level access controls restricting access to router management interfaces
4. Monitor for suspicious DHCP configuration requests and unusual network traffic patterns

COMPENSATING CONTROLS (until patch available):
5. Disable remote management access to affected routers; use only local console access
6. Implement firewall rules blocking external access to port 80/443 on router management interfaces
7. Deploy IDS/IPS signatures detecting buffer overflow attempts targeting /goform/GstDhcpSetSer endpoint
8. Restrict DHCP configuration changes to authorized administrators only
9. Enable router logging and forward logs to centralized SIEM for analysis

DETECTION RULES:
- Monitor HTTP POST requests to /goform/GstDhcpSetSer with oversized 'dips' parameter values
- Alert on unexpected process execution or memory corruption patterns on router devices
- Track failed authentication attempts to router management interfaces

LONG-TERM:
10. Plan immediate replacement of Tenda F1202 devices with patched alternatives or alternative vendors
11. Contact Tenda for patch availability timeline and interim security updates
12. Evaluate firmware alternatives or hardware replacement options
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة التوجيه Tenda F1202 التي تعمل بالإصدار 1.2.0.20(408) في شبكتك باستخدام أدوات المسح
2. عزل أجهزة التوجيه المتأثرة عن الأنظمة الحرجة وتقسيم الوصول إلى الشبكة
3. تطبيق عناصر تحكم الوصول على مستوى الشبكة لتقييد الوصول إلى واجهات إدارة جهاز التوجيه
4. مراقبة طلبات إعدادات DHCP المريبة وأنماط حركة الشبكة غير العادية

عناصر التحكم التعويضية (حتى توفر التصحيح):
5. تعطيل الوصول الإداري البعيد إلى أجهزة التوجيه المتأثرة؛ استخدام وصول وحدة التحكم المحلية فقط
6. تطبيق قواعد جدار الحماية لحظر الوصول الخارجي إلى المنافذ 80/443 على واجهات إدارة جهاز التوجيه
7. نشر توقيعات IDS/IPS للكشف عن محاولات تجاوز المخزن المؤقت التي تستهدف نقطة نهاية /goform/GstDhcpSetSer
8. تقييد تغييرات إعدادات DHCP للمسؤولين المصرح لهم فقط
9. تفعيل تسجيل جهاز التوجيه وإعادة توجيه السجلات إلى نظام SIEM مركزي للتحليل

قواعد الكشف:
- مراقبة طلبات HTTP POST إلى /goform/GstDhcpSetSer بقيم معاملات 'dips' كبيرة الحجم
- تنبيه عند تنفيذ عملية غير متوقعة أو أنماط تلف الذاكرة على أجهزة التوجيه
- تتبع محاولات المصادقة الفاشلة على واجهات إدارة جهاز التوجيه

المدى الطويل:
10. التخطيط للاستبدال الفوري لأجهزة Tenda F1202 بدائل معدلة أو بائعين بدلاء
11. الاتصال بـ Tenda للحصول على الجدول الزمني لتوفر التصحيح والتحديثات الأمنية المؤقتة
12. تقييم بدائل البرامج الثابتة أو خيارات استبدال الأجهزة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - Monitoring and logging of network access
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.IP-12 - Security awareness and training for patch management DE.CM-1 - Detection and monitoring of network anomalies
🟡 ISO 27001:2022
A.12.3.1 - Segregation of networks A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development and change management
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches and updates Requirement 11.2 - Vulnerability scanning and assessment
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-119
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-05-25
Source Feed nvd
🇸🇦 Saudi Risk Score
8.9
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-119
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.