CVE-2025-29100
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 24, 2025
Updated: Apr 1, 2025
CWE ID 121
Summary
CVE-2025-29100 is a buffer overflow vulnerability affecting the Tenda AC8 router with firmware version V16.03.34.06. The issue lies in the 'fromSetRouteStatic' function where an incorrect input validation leads to an excessive amount of data being written to a fixed-size buffer. This condition can be exploited by an attacker to execute arbitrary code or cause the device to crash, potentially leading to unauthorized access or denial of service. Users are advised to update their router firmware to a non-vulnerable version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd