CVE-2025-63834

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/11/2025
Last modified:
12/11/2025

Description

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.

Impact