PT-2025-47105 · Tenda · Tenda Ac20

Yun Zhang

·

Published

2025-11-17

·

Updated

2025-11-22

·

CVE-2025-13258

CVSS v2.0
9.0
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC20 versions up to 16.03.08.12
Description A buffer overflow exists in the Tenda AC20 router. The issue is located in an unknown function within the
/goform/WifiExtraSet
file. Manipulation of the
wpapsk crypto
argument can trigger the overflow, allowing for remote code execution. The exploit for this issue is publicly available.
Recommendations Versions up to 16.03.08.12 should be updated to a newer, secure version as soon as possible. As a temporary workaround, restrict access to the
/goform/WifiExtraSet
endpoint to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-13258

Affected Products

Tenda Ac20