CVE-2025-29137

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 19, 2025
Updated: Apr 1, 2025
CWE ID 120

Summary

CVE-2025-29137 is a newly disclosed vulnerability affecting Tenda AC7 routers running V1.0 V15.03.06.44 firmware. The issue stems from a buffer overflow flaw in the form_fast_setting_wifi_set function, which is triggered by an incorrect timeZone parameter input. This vulnerability can potentially lead to remote code execution (RCE), posing a significant risk to network security. Attackers could exploit this weakness to gain unauthorized access and control over the affected routers. Users are advised to update their firmware as soon as a patch becomes available to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share