CVE-2025-29101
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-29101 is a stack overflow vulnerability affecting Tenda AC8V4.0 V16.03.34.06. This issue is located in the get_parentControl_list_Info function, where the deviceid parameter is processed. An attacker can exploit this flaw by sending maliciously crafted input to induce a buffer overflow condition, leading to potential code injection or denial-of-service attacks. Successful exploitation could enable an attacker to gain unauthorized access or control over the device. Users are strongly advised to apply the necessary software patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd