PT-2025-12706 · Tenda · Tenda Ac7

Published

2025-03-24

·

Updated

2025-04-01

·

CVE-2025-29135

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC7 version 15.03.06.44
Description A stack-based buffer overflow vulnerability allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.
Recommendations For Tenda AC7 version 15.03.06.44, consider disabling the formWifiBasicSet function until a patch is available to prevent exploitation. Restrict access to the security parameter of this function to minimize the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-29135

Affected Products

Tenda Ac7