ZeroHour

CVE-2025-63835

PoC
CVSS 3.1
8.8 high
EPSS
<1%p49
Published
()
Modified
Description

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

Vendors
tenda
Products
ac18 firmware
Weakness
CWE-787, CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.