CRITICAL🇵🇱 Wersja polska

CVE-2025-29135

CVSS 9.8v3.1pub. 2025-03-24upd. 2025-04-01

A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.

🤖 AI Analysis
How it works

The vulnerability exists in the formWifiBasicSet function, which improperly handles the 'security' parameter transmitted by the attacker. The lack of proper validation of input data length causes a stack overflow, overwriting critical memory structures. The attacker can craft an appropriate payload and send it remotely without authentication, thereby gaining control over program execution flow and the ability to run arbitrary code.

Impact

An attacker can remotely execute arbitrary code (RCE) with the privileges of the process handling the request, which in practice means complete takeover of the router — including network traffic eavesdropping, configuration changes, malicious software installation, or using the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Until the fix is deployed, it is recommended to restrict access to the device management interface only to trusted IP addresses and block access to the admin panel from the WAN side.

Who is affected

Tenda AC7 with software version V15.03.06.44

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Tenda Ac7

    HW
    Tenda
    1.0
  • Tenda Ac7 Firmware

    OS
    Tenda
    15.03.06.44
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2018-14558CRITICAL9.8⚠ KEVPL ✓same product

Command Injection w routerach Tenda AC7/AC9/AC10 via setUsbUnload

CVE-2026-51843CRITICAL9.8PL ✓same product

Stack buffer overflow w Tenda AC7 via parametr wanMTU

CVE-2026-51845CRITICAL9.8PL ✓same product

Stack buffer overflow w Tenda AC7 via parametr mac (/goform/AdvSetMacMtuWan)

CVE-2026-51844CRITICAL9.8PL ✓same product

Stack buffer overflow w Tenda AC7 — interfejs AdvSetMacMtuWan

CVE-2026-51846CRITICAL9.8PL ✓same product

Stack buffer overflow w Tenda AC7 — RCE przez parametr wanSpeed