Tenda · Tenda Ac21 · CVE-2025-13446
**Name of the Vulnerable Software and Affected Versions**
Tenda AC21 version 16.03.08.16
**Description**
A flaw exists in Tenda AC21 version 16.03.08.16 related to a stack-based buffer overflow. The issue is located in the file `/goform/SetSysTimeCfg`. The `timeZone/time` argument can be manipulated to trigger the overflow, allowing for remote exploitation. The exploit has been publicly disclosed.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.