PT-2025-12369 · Tenda · Tenda W18E

Published

2025-03-20

·

Updated

2025-03-26

·

CVE-2025-29218

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda W18E version 2.0 v16.01.0.11
Description A stack overflow was discovered in the wifiPwd parameter at the /goform/setModules API endpoint. This issue allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Recommendations For Tenda W18E version 2.0 v16.01.0.11, as a temporary workaround, consider disabling the /goform/setModules API endpoint or restricting access to the wifiPwd parameter until a patch is available. Avoid using the wifiPwd parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04726
CVE-2025-29218

Affected Products

Tenda W18E