CVE-2025-1814

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 2, 2025
Updated: Mar 5, 2025
CWE ID 119
CWE ID 121

Summary

CVE-2025-1814 is a critical vulnerability discovered in Tenda AC6's firmware version 15.03.05.16. This issue impacts an unnamed functionality within the /goform/WifiExtraSet file. An attacker can exploit this flaw by manipulating the wpapsk_crypto argument to trigger a stack-based buffer overflow. The vulnerability is remotely exploitable, and the exploit code has been disclosed to the public, increasing the risk for potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Tenda AC6

Affected Vendors

  • Shenzhen Tenda Technology Co. Ltd