Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Raining-101

#28525of 53,625
9Total CVSS
Vulnerabilities · 1
PT-2025-9253
9.0
2025-02-21
Tenda · Tenda Ac7 · CVE-2025-1851
**Name of the Vulnerable Software and Affected Versions** Tenda AC7 versions up to 15.03.06.44 **Description** A critical vulnerability was found in Tenda AC7, affecting the function `formSetFirewallCfg` of the file `/goform/SetFirewallCfg`. The manipulation of the argument `firewallEn` leads to a stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. **Recommendations** For Tenda AC7 versions up to 15.03.06.44, as a temporary workaround, consider disabling the `formSetFirewallCfg` function until a patch is available. Restrict access to the `/goform/SetFirewallCfg` endpoint to minimize the risk of exploitation. Avoid using the `firewallEn` argument in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.