CVE-2025-11527

Severity CVSS v4.0:
HIGH
Type:
CWE-119 Buffer Errors
Publication date:
09/10/2025
Last modified:
14/10/2025

Description

A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fast_setting_pppoe_set. Executing manipulation of the argument Password can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:*