CVE-2025-29100

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 24, 2025
Updated: Apr 1, 2025
CWE ID 121

Summary

CVE-2025-29100 is a buffer overflow vulnerability affecting the Tenda AC8 router with firmware version V16.03.34.06. The issue lies in the 'fromSetRouteStatic' function where an incorrect input validation leads to an excessive amount of data being written to a fixed-size buffer. This condition can be exploited by an attacker to execute arbitrary code or cause the device to crash, potentially leading to unauthorized access or denial of service. Users are advised to update their router firmware to a non-vulnerable version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share