CVE-2025-29149

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
Updated: Mar 27, 2025
CWE ID 121

Summary

CVE-2025-29149 is a newly discovered buffer overflow vulnerability affecting Tenda i12 V1.0.0.10(3805). The issue lies in the formSetAutoPing function, which contains a flaw in handling the ping1 parameter. An attacker can exploit this vulnerability by sending maliciously crafted data to the affected device, potentially leading to unintended code execution or denial-of-service conditions. Successful exploitation could result in unauthorized access, data theft, or device compromise. Users are strongly advised to apply the necessary patches or updates as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share