PT-2025-4073 · Tenda · Tenda Ac18
Alc9700
·
Published
2025-01-20
·
Updated
2025-01-30
·
CVE-2025-0848
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda A18 versions up to 15.13.07.09
Description
This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument
wpapsk crypto5g leads to stack-based buffer overflow. The attack may be initiated remotely.Recommendations
Tenda A18 versions up to 15.13.07.09: Update the firmware to a version later than 15.13.07.09 to resolve the issue.
As a temporary workaround, consider restricting access to the /goform/SetCmdlineRun endpoint until a patch is available.
Avoid using the parameter
wpapsk crypto5g in the affected API endpoint until the issue is resolved.Exploit
Fix
Stack Overflow
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac18