PT-2025-35174 · Tenda · Tenda Ac21 +1

Lxyilu

·

Published

2025-08-17

·

Updated

2025-09-03

·

CVE-2025-9605

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC21 version 16.03.08.16 Tenda AC23 version 16.03.08.16
Description A stack-based buffer overflow vulnerability exists in the
GetParentControlInfo
function of the
/goform/GetParentControlInfo
file in Tenda AC21 and AC23 routers. Manipulation of the
mac
argument can trigger the overflow, allowing for remote exploitation. The exploit has been publicly disclosed.
Recommendations For Tenda AC21 version 16.03.08.16, disable remote management and segment networks. For Tenda AC23 version 16.03.08.16, disable remote management and segment networks.

Exploit

Fix

RCE

Buffer Overflow

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10636
CVE-2025-9605

Affected Products

Tenda Ac21
Tenda Ac23