PT-2025-40873 · Tenda · Tenda Ac18

Wxhwxhwxh

·

Published

2025-09-28

·

Updated

2025-10-06

·

CVE-2025-11327

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC18 version 15.03.05.19(6318)
Description A stack-based buffer overflow exists in the Tenda AC18 device. The issue is located in the /goform/SetUpnpCfg file and involves the manipulation of the upnpEn argument. This allows for remote exploitation of the device. The exploit for this issue has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13236
CVE-2025-11327

Affected Products

Tenda Ac18