PT-2025-35174 · Tenda · Tenda Ac21 +1
Lxyilu
·
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2025-9605
Lxyilu
·
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2025-9605
10
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Tenda AC21 version 16.03.08.16
Tenda AC23 version 16.03.08.16
Description:
A stack-based buffer overflow vulnerability exists in the `GetParentControlInfo` function of the `/goform/GetParentControlInfo` file in Tenda AC21 and AC23 routers. Manipulation of the `mac` argument can trigger the overflow, allowing for remote exploitation.
Recommendations:
Tenda AC21 version 16.03.08.16: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Tenda AC23 version 16.03.08.16: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Stack Overflow
Buffer Overflow