PT-2025-30682 · Tenda · Tenda Ac8V4

Published

2025-07-24

·

Updated

2025-07-24

·

CVE-2025-51089

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tenda AC8V4 version V16.03.34.06
Description The device contains a heap overflow at the /goform/GetParentControlInfo API endpoint. Manipulation of the mac parameter leads to a heap-based buffer overflow.
Recommendations Apply a newer version of Tenda AC8V4 that addresses this issue. As a temporary workaround, restrict access to the /goform/GetParentControlInfo API endpoint.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10209
CVE-2025-51089

Affected Products

Tenda Ac8V4