CVE-2025-28221

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 28, 2025
Updated: Apr 21, 2025
CWE ID 120

Summary

CVE-2025-28221 is a buffer overflow vulnerability affecting Tenda W6\_S v1.0.0.4\_510. The issue lies in the set\_local\_time function, which can be exploited by remote attackers. By passing maliciously crafted time data through a POST request, they can cause the web server to crash due to the buffer overflow condition. This vulnerability poses a significant risk of denial-of-service attacks. To mitigate this issue, users are strongly advised to update their Tenda W6\_S devices to a non-affected version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share