CVE-2025-45429

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 30, 2025
CWE ID 121

Summary

CVE-2025-45429 is a newly identified vulnerability affecting the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi. This issue involves a stack overflow in the /goform/WifiWpsStart function, which can be exploited remotely to execute arbitrary code. An attacker could potentially take advantage of this vulnerability to gain unauthorized access to the router and carry out malicious activities, such as data theft or unauthorized network access. The stack overflow vulnerability in this router model poses a significant risk to users and requires urgent attention for patching or mitigation measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Tenda AC9

Affected Vendors

  • Shenzhen Tenda Technology Co. Ltd