CVE-2025-14993
Severity CVSS v4.0:
HIGH
Type:
CWE-119
Buffer Errors
Publication date:
21/12/2025
Last modified:
21/12/2025
Description
A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation of the argument scanList results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
Impact
Base Score 4.0
7.40
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_AC18/SetDlnaCfg/SetDlnaCfg.md
- https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_AC18/SetDlnaCfg/SetDlnaCfg.md#reproduce
- https://vuldb.com/?ctiid_337687=
- https://vuldb.com/?id_337687=
- https://vuldb.com/?submit_719084=
- https://www.tenda.com.cn/



