PT-2025-47105 · Tenda · Tenda Ac20
Yun Zhang
·
Published
2025-11-16
·
Updated
2025-11-22
·
CVE-2025-13258
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC20 versions up to 16.03.08.12
Description
A buffer overflow exists in the Tenda AC20 router. The issue is located in an unknown function within the
/goform/WifiExtraSet file. Manipulation of the wpapsk crypto argument can trigger the overflow, allowing for remote code execution. The exploit for this issue is publicly available.Recommendations
Versions up to 16.03.08.12 should be updated to a newer, secure version as soon as possible. As a temporary workaround, restrict access to the
/goform/WifiExtraSet endpoint to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac20