PT-2025-52850 · Tenda · Tenda Wh450

Z472421519

·

Published

2025-12-23

·

Updated

2025-12-24

·

CVE-2025-15046

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda WH450 version 1.0.0.18
Description A stack-based buffer overflow exists in the HTTP Request Handler component of the Tenda WH450. The issue is located in the /goform/PPTPClient file and can be triggered by manipulating the netmsk argument. This allows for remote exploitation of the device. The exploit has been publicly disclosed. The vulnerable function is unknown.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

RCE

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-15046

Affected Products

Tenda Wh450