PT-2025-30670 · Tenda · Tenda Ac8V4

Published

2025-07-24

·

Updated

2025-07-24

·

CVE-2025-51085

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Tenda AC8V4 version V16.03.34.06
Description The Tenda AC8V4 device contains a stack overflow issue at the /goform/SetSysTimeCfg API endpoint. Manipulation of the timeZone and timeType parameters leads to a stack-based buffer overflow.
Recommendations Apply a software update to address the issue in the affected version. As a temporary workaround, restrict access to the /goform/SetSysTimeCfg API endpoint.

Exploit

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-51085

Affected Products

Tenda Ac8V4