CVE-2025-25667
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 20, 2025
Updated: Feb 21, 2025
CWE ID 120
Summary
CVE-2025-25667 is a stack overflow vulnerability affecting Tenda AC8V4 V16.03.34.06 firmware. The issue lies in the function get_parentControl_list_Info, which can be manipulated through the urls parameter to cause an overflow, potentially leading to unintended code execution or denial of service. This vulnerability can be exploited remotely, posing a significant risk to network security. It is recommended that users of Tenda AC8V4 update their firmware to a version that addresses this issue as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share